npm · registry.npmjs.org
@onum-releases/api-client
DNS / OAST exfiltration: matched "oastify.com"
Early detection
PkgRadar flagged this 4h before public disclosure
Detected 2026-06-18 · disclosed as MAL-2026-6122 on 2026-06-18
Why PkgRadar flagged 1.0.3
| Severity | Signal | Evidence |
|---|---|---|
| high | DNS / OAST exfiltration | matched "oastify.com" · package/index.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.3 | High risk | 30 | 2026-06-19 |
1.0.2 | High risk | 30 | 2026-06-19 |
1.0.1 | High risk | 30 | 2026-06-19 |
Block this in CI
pkgradar gate --ecosystem npm @onum-releases/[email protected]