PkgRadar

npm · registry.npmjs.org

@qqbrowser/openclaw-qbot

Credential File Packaged: package/node_modules/bottleneck/.env

Why PkgRadar flagged 0.10.18

SeveritySignalEvidence
highCredential File Packagedpackage/node_modules/bottleneck/.env · package/node_modules/bottleneck/.env
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/compat.cjs
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/index.cjs
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/telegram.cjs
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/api-BeG0ObSq.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/api-Dx8x1KTs.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/compat.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/node_modules/@whiskeysockets/baileys/lib/Utils/generics.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/index.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/telegram.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.18High risk2472026-06-10
0.10.13High risk2472026-06-10
0.11.61High risk2472026-06-10
0.10.17High risk2472026-06-10
0.10.12High risk2472026-06-10
0.10.16High risk2472026-06-10
0.10.15High risk2472026-06-10

Block this in CI

PkgRadar gates @qqbrowser/openclaw-qbot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @qqbrowser/[email protected]