PkgRadar

npm · registry.npmjs.org

@onekeyfe/hd-core

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 1.1.27-alpha.37

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/src/utils/networkUtils.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.27-alpha.37High risk202026-06-13
1.1.27-alpha.36High risk202026-06-13
1.2.0-alpha.0High risk202026-06-11
1.1.27-patch.1High risk252026-06-11
1.1.27-alpha.4High risk252026-06-10
1.1.27-alpha.35High risk202026-06-10
1.1.27-alpha.34High risk202026-06-10
1.1.27High risk252026-06-10
1.1.27-alpha.45High risk202026-06-10
1.1.27-alpha.7High risk252026-06-10
1.1.27-alpha.43High risk202026-06-10
1.1.27-alpha.42High risk202026-06-10
1.1.27-alpha.6High risk252026-06-10
1.1.27-alpha.100High risk252026-06-10
1.1.27-alpha.41High risk202026-06-10
1.1.27-alpha.5High risk252026-06-10
1.1.27-alpha.39High risk202026-06-10
1.1.27-alpha.40High risk202026-06-10
1.1.27-alpha.38High risk202026-06-10
1.1.27-alpha.101High risk252026-06-10
1.1.27-alpha.3High risk252026-06-10
1.1.27-alpha.2High risk252026-06-10
1.1.27-alpha.1Review502026-05-25
1.1.26-patch.2Low risk02026-05-25
1.1.27-alpha.33Low risk02026-05-25
1.1.26-patch.1Low risk02026-05-25

Block this in CI

PkgRadar gates @onekeyfe/hd-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @onekeyfe/[email protected]