PkgRadar

npm · registry.npmjs.org

@openlife/cli

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 1.21.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/index.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/orchestrator/Gateway.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/index.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/orchestrator/SystemDoctor.js
mediumCredential file accessmatched ".npmrc" · package/dist/util/npmrc.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.21.0High risk1162026-06-13
1.20.0High risk1162026-06-13
1.19.7High risk812026-06-10
1.19.8High risk812026-06-10
1.19.3High risk812026-06-10
1.22.0High risk812026-06-10
1.19.2Review232026-05-25
1.19.1Review232026-05-25
1.18.3Review202026-05-25
1.19.0Review232026-05-25

Block this in CI

PkgRadar gates @openlife/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openlife/[email protected]