PkgRadar

npm · registry.npmjs.org

@openclaw/diagnostics-otel

DNS / OAST exfiltration: matched "dns.lookup"

Why PkgRadar flagged 2026.5.27

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.lookup" · package/node_modules/@opentelemetry/semantic-conventions/build/esm/experimental_metrics.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/node_modules/@opentelemetry/semantic-conventions/build/esnext/experimental_metrics.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/node_modules/@opentelemetry/semantic-conventions/build/src/experimental_metrics.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/node_modules/@grpc/grpc-js/build/src/resolver-dns.js
highDNS / OAST exfiltrationmatched "dns.resolveTxt" · package/node_modules/@grpc/grpc-js/build/src/service-config.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/node_modules/@grpc/grpc-js/src/resolver-dns.ts
highDNS / OAST exfiltrationmatched "dns.resolveTxt" · package/node_modules/@grpc/grpc-js/src/service-config.ts
mediumObfuscation Densityhigh encoded/escaped-token density · package/node_modules/lodash.camelcase/index.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/node_modules/cjs-module-lexer/lexer.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/npm-shrinkwrap.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.6Low risk02026-06-12
2026.6.6-beta.2Low risk02026-06-12
2026.6.6-beta.1Low risk02026-06-11
2026.6.5Low risk02026-06-09
2026.6.5-beta.6Low risk02026-06-09
2026.6.5-beta.5Low risk02026-06-08
2026.6.5-beta.3Low risk02026-06-08
2026.6.5-beta.2Low risk02026-06-07
2026.6.5-beta.1Low risk02026-06-06
2026.6.2-beta.1Low risk02026-06-04
2026.6.1Low risk02026-06-03
2026.6.1-beta.3Low risk02026-06-03
2026.6.1-beta.2Low risk02026-06-02
2026.6.1-beta.1Low risk02026-06-01
2026.5.31-beta.4Low risk02026-06-01
2026.5.31-beta.3Low risk02026-05-31
2026.5.31-beta.2Low risk02026-05-31
2026.5.31-beta.1Low risk02026-05-31
2026.5.30-beta.1Low risk02026-05-31
2026.5.28Low risk02026-05-30
2026.5.25-beta.1Low risk02026-05-30
2026.5.28-beta.4Low risk02026-05-29
2026.5.28-beta.3Low risk02026-05-29
2026.5.28-beta.2Low risk02026-05-29
2026.5.28-beta.1Low risk02026-05-29
2026.5.27Review402026-05-28
2026.5.27-beta.1Review402026-05-28
2026.5.26Review402026-05-27
2026.5.26-beta.2Review402026-05-27
2026.5.26-beta.1Review402026-05-27
2026.5.24-beta.2Review2242026-05-25
2026.5.24-beta.1Review2242026-05-24
2026.5.22Review2242026-05-24
2026.5.20Review122026-05-24

Block this in CI

PkgRadar gates @openclaw/diagnostics-otel (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openclaw/[email protected]