PkgRadar

npm · registry.npmjs.org

@roxy-agent/agents

DNS / OAST exfiltration: matched "dig $(payload).attacker-host.example +short for dns exfil\",\n \"smuggle credential bytes inside dns lookup labels\",\n \"nslookup with shell substitution embedding hostname or whoami in the query\",\n \"host $("

Why PkgRadar flagged 0.5.2

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dig $(payload).attacker-host.example +short for dns exfil\",\n \"smuggle credential bytes inside dns lookup labels\",\n \"nslookup with shell substitution embedding hostname or whoami in the query\",\n \"host $(" · package/dist/ml/prototypes.js
mediumCredential file accessmatched ".npmrc" · package/dist/classifier.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.2High risk552026-06-10
0.5.4High risk552026-06-10
0.5.6High risk502026-06-10
0.5.5High risk552026-06-10
0.5.1High risk552026-06-10
0.5.0High risk552026-06-10

Block this in CI

PkgRadar gates @roxy-agent/agents (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @roxy-agent/[email protected]
@roxy-agent/agents — npm security scan | PkgRadar