PkgRadar

npm · registry.npmjs.org

@open-mercato/carrier-inpost

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 1.0.0-canary.20260604121941.6384b3e

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/modules/carrier_inpost/webhook-guide.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/src/modules/carrier_inpost/webhook-guide.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-canary.20260604121941.6384b3eHigh risk502026-06-04
1.0.0-canary.20260604122351.e841699High risk502026-06-04
1.0.0-canary.20260604063518.74d2590High risk502026-06-04
1.0.0-canary.20260508062129.407907bHigh risk502026-06-04
1.0.0-canary.20260604063344.a32d138High risk502026-06-04

Block this in CI

PkgRadar gates @open-mercato/carrier-inpost (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @open-mercato/[email protected]