PkgRadar

npm · registry.npmjs.org

@pipedream/sdk

Webhook Exfil Endpoint: matched "pipedream.net"

Why PkgRadar flagged 3.0.7

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "pipedream.net" · package/dist/cjs/api/resources/workflows/client/Client.js
highWebhook Exfil Endpointmatched "pipedream.net" · package/dist/esm/api/resources/workflows/client/Client.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.7High risk252026-06-10
3.1.0High risk252026-06-10
3.0.9Review152026-05-30
3.0.8Review152026-05-28
3.0.6Review152026-05-27

Block this in CI

PkgRadar gates @pipedream/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pipedream/[email protected]