PkgRadar

npm · registry.npmjs.org

@stackable-labs/embeddables

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 2.24.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/react.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/stackable-widget.external.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/stackable-widget.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.24.0High risk502026-06-13
2.23.0High risk352026-06-10
2.22.0High risk352026-06-10
2.21.1High risk502026-06-10
2.20.0High risk352026-06-10
2.21.0High risk352026-06-10
3.0.1High risk352026-06-10
3.0.0High risk352026-06-10
2.30.0High risk352026-06-10
2.29.0High risk352026-06-10
2.28.0High risk352026-06-10
2.27.0High risk502026-06-10
2.25.2High risk352026-06-10
2.26.0High risk352026-06-10
2.25.1High risk502026-06-10
2.25.0High risk352026-06-10

Block this in CI

PkgRadar gates @stackable-labs/embeddables (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @stackable-labs/[email protected]