PkgRadar

npm · registry.npmjs.org

@rsb1813/sharpclaw

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 2026.6.3

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/i18n-C0k1rM_n.js
highNew Account With Lifecycle Hookpackage first published 0 day(s) ago, 2 total version(s), has lifecycle hook · package.json
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-N-Rn40jr.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-install-env-CSqfL5Dl.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-managed-root-CXoJMYTJ.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.3High risk1332026-06-18
2026.6.2High risk1332026-06-18

Block this in CI

PkgRadar gates @rsb1813/sharpclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @rsb1813/[email protected]