PkgRadar

npm · registry.npmjs.org

@rubytech/create-maxy-code

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.1.328

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/payload/server/server.js
mediumRemote Payloadmatched "curl " · package/dist/index.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/payload/platform/plugins/telegram/mcp/dist/index.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/payload/server/server.js
mediumRemote Payloadmatched "curl " · package/payload/platform/plugins/workflows/mcp/test-workflows.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.328High risk652026-06-17
0.1.327High risk652026-06-17
0.1.326High risk932026-06-17
0.1.325High risk932026-06-17
0.1.324High risk932026-06-17
0.1.323High risk932026-06-15
0.1.322High risk652026-06-15
0.1.321High risk932026-06-15
0.1.320High risk932026-06-15
0.1.319High risk652026-06-14
0.1.318High risk652026-06-14
0.1.317High risk932026-06-14
0.1.316High risk652026-06-14
0.1.315High risk652026-06-14
0.1.314High risk932026-06-14
0.1.313High risk652026-06-13
0.1.312High risk652026-06-13
0.1.311High risk652026-06-13
0.1.310High risk652026-06-13
0.1.309High risk652026-06-13
0.1.308High risk932026-06-13
0.1.307High risk932026-06-13
0.1.305High risk652026-06-13
0.1.306High risk652026-06-13
0.1.304High risk932026-06-12
0.1.303High risk932026-06-12
0.1.302High risk652026-06-12
0.1.301High risk652026-06-12
0.1.300High risk932026-06-12
0.1.299High risk932026-06-12
0.1.298High risk932026-06-11
0.1.297High risk932026-06-11
0.1.296High risk652026-06-11
0.1.295High risk932026-06-11
0.1.294High risk932026-06-11
0.1.293High risk932026-06-11
0.1.292High risk932026-06-11
0.1.291High risk652026-06-11
0.1.290High risk652026-06-10
0.1.289High risk932026-06-10
0.1.288High risk932026-06-10
0.1.287High risk652026-06-10
0.1.286High risk652026-06-10
0.1.285High risk652026-06-10
0.1.284High risk652026-06-10
0.1.283High risk652026-06-10
0.1.282Review412026-06-09
0.1.280Review282026-06-08
0.1.281Review282026-06-08
0.1.279Review282026-06-08
0.1.277Review282026-06-08
0.1.278Review282026-06-08
0.1.276Review282026-06-07
0.1.275Review372026-06-07
0.1.274Review372026-06-07
0.1.273Review372026-06-07
0.1.272Review372026-06-07
0.1.271Review372026-06-07
0.1.270Review532026-06-07
0.1.269Review372026-06-07
0.1.268Review372026-06-07
0.1.267Review372026-06-07
0.1.266Review372026-06-07
0.1.265Review372026-06-06
0.1.264Review372026-06-06
0.1.263Review372026-06-06
0.1.259Review532026-06-06
0.1.258Review372026-06-06
0.1.257Review372026-06-06
0.1.256Review372026-06-06
0.1.255Review452026-06-05
0.1.254Review452026-06-04
0.1.253Review452026-06-04
0.1.251Review452026-06-04
0.1.252Review452026-06-04
0.1.249Review462026-06-04
0.1.248Review462026-06-04
0.1.247Review462026-06-04
0.1.246Review452026-06-04
0.1.244Review452026-06-04
0.1.243Review322026-06-02
0.1.241Review322026-06-02
0.1.242Review322026-06-02
0.1.240Review322026-06-02
0.1.238Review322026-06-02
0.1.239Review322026-06-02
0.1.236Review322026-06-02
0.1.237Review652026-06-02
0.1.235Review322026-06-02
0.1.234Review322026-06-02
0.1.233Review322026-06-02
0.1.232Review322026-06-01
0.1.230Review322026-06-01
0.1.228Review652026-06-01
0.1.229Review322026-06-01
0.1.227Review322026-06-01
0.1.226Review652026-06-01
0.1.225Review322026-06-01
0.1.224Review322026-06-01
0.1.223Review322026-05-31
0.1.222Review322026-05-31
0.1.221Review322026-05-31
0.1.219Review322026-05-31
0.1.216Review322026-05-31
0.1.214Review322026-05-31
0.1.212Review322026-05-31
0.1.210Review322026-05-31
0.1.208Review322026-05-30
0.1.206Review322026-05-30
0.1.204Review322026-05-30
0.1.203Review322026-05-30
0.1.187Review322026-05-30
0.1.185Review322026-05-30
0.1.186Review322026-05-30
0.1.183Review322026-05-30
0.1.184Review322026-05-30
0.1.200Review322026-05-30
0.1.198Review322026-05-30
0.1.197Review322026-05-30
0.1.196Review322026-05-30
0.1.195Review322026-05-30
0.1.194Review322026-05-30
0.1.193Review322026-05-30
0.1.192Review322026-05-30
0.1.190Review322026-05-29
0.1.191Review322026-05-29
0.1.189Review322026-05-29
0.1.188Review322026-05-29
0.1.181Review492026-05-27
0.1.182Review492026-05-27
0.1.177Review492026-05-27
0.1.179Review492026-05-27
0.1.171Review682026-05-27
0.1.172Review682026-05-27
0.1.148Review602026-05-26
0.1.146Review602026-05-26
0.1.147Review602026-05-26
0.1.143Review602026-05-25
0.1.144Review602026-05-25
0.1.140Review602026-05-25
0.1.132Review602026-05-25
0.1.138Review602026-05-25
0.1.115Review982026-05-25
0.1.114Review622026-05-25
0.1.113Review672026-05-25
0.1.112Review922026-05-25
0.1.111Review922026-05-24
0.1.110Review922026-05-24
0.1.109Review1122026-05-24
0.1.108Review1122026-05-24
0.1.107Review1122026-05-24
0.1.106Review1122026-05-24
0.1.105Review1122026-05-24
0.1.104Review1122026-05-24
0.1.102Review1122026-05-24
0.1.103Review1122026-05-24

Block this in CI

PkgRadar gates @rubytech/create-maxy-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @rubytech/[email protected]