PkgRadar

npm · registry.npmjs.org

@onekeyfe/hd-web-sdk

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 1.1.27-alpha.37

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/build/js/iframe.843f3d6909cdf977db27.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/build/onekey-js-sdk.min.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.27-alpha.37High risk252026-06-13
1.1.27-alpha.36High risk252026-06-13
1.1.28High risk252026-06-12
1.1.27-patch.1High risk252026-06-11
1.1.27-alpha.4High risk252026-06-10
1.1.27-alpha.35High risk252026-06-10
1.1.27-alpha.34High risk252026-06-10
1.1.27High risk252026-06-10
1.1.27-alpha.45High risk252026-06-10
1.1.27-alpha.7High risk252026-06-10
1.1.27-alpha.43High risk252026-06-10
1.1.27-alpha.42High risk252026-06-10
1.1.27-alpha.6High risk252026-06-10
1.1.27-alpha.100High risk252026-06-10
1.1.27-alpha.41High risk252026-06-10
1.1.27-alpha.5High risk252026-06-10
1.1.27-alpha.39High risk252026-06-10
1.1.27-alpha.40High risk252026-06-10
1.1.27-alpha.38High risk252026-06-10
1.1.27-alpha.101High risk252026-06-10
1.1.27-alpha.3High risk252026-06-10
1.1.27-alpha.2High risk252026-06-10
1.1.27-alpha.1Review602026-05-25
1.1.26-patch.2Review102026-05-25
1.1.27-alpha.33Review102026-05-25
1.1.26-patch.1Review102026-05-25

Block this in CI

PkgRadar gates @onekeyfe/hd-web-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @onekeyfe/[email protected]