PkgRadar

npm · registry.npmjs.org

@nikolasp98/minion

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 2026.5.14-dev

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/extensions/voice-call/index.js
highWebhook Exfil Endpointmatched "ngrok.app" · package/extensions/voice-call/src/providers/twilio.test.ts
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/extensions/voice-call/src/webhook-security.test.ts
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/extensions/voice-call/src/webhook-security.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/doctor-config-flow-Bjp-kG-P.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/doctor-config-flow-BzhGV6KM.js
mediumRemote Payloadmatched "curl " · package/extensions/nitter/setup/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.5.14-devHigh risk1762026-06-12
2026.5.15-devHigh risk1862026-06-12
2026.5.16-devHigh risk1862026-06-12
2026.5.17-devHigh risk1862026-06-12
2026.6.10-dev.20260612164123High risk2202026-06-12

Block this in CI

PkgRadar gates @nikolasp98/minion (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nikolasp98/[email protected]