npm · registry.npmjs.org
@solidnumber/cli
Webhook Exfil Endpoint: matched "ngrok.app"
Why PkgRadar flagged 2.13.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Webhook Exfil Endpoint | matched "ngrok.app" · package/dist/commands/webhooks.js |
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"try{if(!process.env.CI)console.log('\\n Solid# CLI installed. Get started: solid setup\\n')}catch(e){}\"" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.13.1 | High risk | 75 | 2026-06-16 |
2.13.0 | High risk | 75 | 2026-06-14 |
2.12.0 | High risk | 75 | 2026-06-12 |
2.11.13 | High risk | 40 | 2026-06-10 |
2.11.12 | High risk | 40 | 2026-06-10 |
2.11.20 | High risk | 75 | 2026-06-10 |
2.11.18 | High risk | 75 | 2026-06-10 |
2.11.17 | High risk | 115 | 2026-06-10 |
2.11.16 | High risk | 40 | 2026-06-10 |
2.11.15 | High risk | 40 | 2026-06-10 |
2.11.14 | High risk | 40 | 2026-06-10 |
2.11.11 | High risk | 40 | 2026-06-10 |
2.11.10 | High risk | 40 | 2026-06-10 |
2.11.5 | Low risk | 0 | 2026-05-25 |
2.11.4 | Low risk | 0 | 2026-05-25 |
2.11.3 | Low risk | 0 | 2026-05-25 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm @solidnumber/[email protected]