PkgRadar

npm · registry.npmjs.org

@openclaw/zalouser

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.6.6

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/node_modules/psl/dist/psl.cjs
highWebhook Exfil Endpointmatched "ngrok.app" · package/node_modules/psl/dist/psl.umd.cjs
highWebhook Exfil Endpointmatched "ngrok.app" · package/node_modules/psl/data/rules.js
highWebhook Exfil Endpointmatched "ngrok.app" · package/node_modules/psl/dist/psl.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.6High risk152026-06-12
2026.6.6-beta.2High risk152026-06-12
2026.6.6-beta.1High risk152026-06-11
2026.5.25-beta.1High risk352026-06-10
2026.6.5Review152026-06-09
2026.6.5-beta.6Review152026-06-09
2026.6.5-beta.5Review152026-06-08
2026.6.5-beta.3Review152026-06-08
2026.6.5-beta.2Review152026-06-07
2026.6.5-beta.1Review152026-06-06
2026.6.2-beta.1Review152026-06-04
2026.6.1Review152026-06-03
2026.6.1-beta.3Review152026-06-03
2026.6.1-beta.2Review152026-06-02
2026.6.1-beta.1Review152026-06-01
2026.5.31-beta.4Review152026-06-01
2026.5.31-beta.3Review152026-05-31
2026.5.31-beta.2Review152026-05-31
2026.5.31-beta.1Review152026-05-31
2026.5.30-beta.1Review152026-05-31
2026.5.28Review152026-05-30
2026.5.28-beta.4Review152026-05-29
2026.5.28-beta.3Review152026-05-29
2026.5.28-beta.2Review152026-05-29
2026.5.28-beta.1Review152026-05-29
2026.5.27Review152026-05-28
2026.5.27-beta.1Review152026-05-28
2026.5.26Review212026-05-27
2026.5.26-beta.2Review212026-05-27
2026.5.26-beta.1Review212026-05-27
2026.5.24-beta.2Review622026-05-25
2026.5.24-beta.1Review622026-05-24
2026.5.22Review622026-05-24
2026.5.20Low risk02026-05-24

Block this in CI

PkgRadar gates @openclaw/zalouser (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openclaw/[email protected]