PkgRadar

npm · registry.npmjs.org

@vellumai/cli

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 0.8.12-dev.202606130730.4d64b75

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/src/commands/pair.ts
mediumRemote Payloadmatched "curl " · package/src/adapters/install.sh
mediumRemote Payloadmatched "curl " · package/src/lib/docker.ts
mediumRemote Payloadmatched "curl " · package/src/lib/local.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.12-dev.202606130730.4d64b75High risk382026-06-13
0.8.12-dev.202606130540.3758c47High risk382026-06-13
0.8.12-dev.202606130318.6b9805dHigh risk382026-06-13
0.8.12-dev.202606130114.203bb30High risk382026-06-13
0.8.12High risk382026-06-12
0.8.12-dev.202606122337.5897832High risk382026-06-12
0.8.12-dev.202606122239.169d5e4High risk382026-06-12
0.8.12-staging.2High risk762026-06-12
0.8.11-dev.202606122104.e5b9dd5High risk382026-06-12
0.8.11-dev.202606122052.009469eHigh risk762026-06-12
0.8.11-dev.202606122025.f06346fHigh risk762026-06-12
0.8.11-dev.202606121945.5dce801High risk762026-06-12
0.8.11-dev.202606121851.26d5122High risk382026-06-12
0.8.11-dev.202606121625.5541181High risk382026-06-12
0.8.11-dev.202606121512.871577High risk762026-06-12
0.8.11-dev.202606121500.871577High risk762026-06-12
0.8.12-staging.1High risk762026-06-12
0.8.11-dev.202606121323.6ac9407High risk382026-06-12
0.8.11-dev.202606121124.ef8e25aHigh risk382026-06-12
0.8.11-dev.202606120935.ef8e25aHigh risk762026-06-12
0.8.11-dev.202606120751.ef8e25aHigh risk762026-06-12
0.8.11-dev.202606120544.842c4c6High risk762026-06-12
0.8.11-dev.202606120321.552e02eHigh risk762026-06-12
0.8.11-dev.202606120116.b9ee95bHigh risk762026-06-12
0.8.11-dev.202606120012.5656fc7High risk762026-06-12
0.8.11-dev.202606112338.1c15e19High risk762026-06-11
0.8.11-dev.202606112241.9ae2fdcHigh risk762026-06-11
0.8.11-dev.202606112147.04177acHigh risk762026-06-11
0.8.11-dev.202606112057.e4bc22eHigh risk762026-06-11
0.8.11High risk762026-06-11
0.8.10-dev.202606111910.ead7030High risk762026-06-11
0.8.10-dev.202606111724.d4e5462High risk762026-06-11
0.8.10-dev.202606111519.39ad418High risk762026-06-11
0.8.11-staging.1High risk762026-06-11
0.8.10-dev.202606111334.d8a7740High risk762026-06-11
0.8.10-dev.202606111255.73ec993High risk762026-06-11
0.8.10-dev.202606111245.be4218bHigh risk762026-06-11
0.8.10-dev.202606111140.6a5e88cHigh risk762026-06-11
0.8.10-dev.202606110941.6cb149dHigh risk762026-06-11
0.8.10-dev.202606110755.6cb149dHigh risk762026-06-11
0.8.10-dev.202606110544.2aed335High risk762026-06-11
0.8.10-dev.202606110422.8c0e9aaHigh risk762026-06-11
0.8.10-dev.202606110317.792ac3cHigh risk762026-06-11
0.8.10-dev.202606110240.ef9212eHigh risk762026-06-11
0.8.10-dev.202606110112.319a8d3High risk762026-06-11
0.8.10-dev.202606110059.319a8d3High risk762026-06-11
0.8.10-dev.202606102342.319a8d3High risk762026-06-11
0.8.10-dev.202606102253.fbea648High risk762026-06-10
0.8.10-dev.202606102242.5285563High risk762026-06-10
0.8.10-dev.202606102225.a3947deHigh risk762026-06-10
0.8.10-dev.202606102147.02afd31High risk762026-06-10
0.8.10-dev.202606102100.3beeffcHigh risk762026-06-10
0.8.10-dev.202606101903.31e26e6High risk762026-06-10
0.8.10-dev.202606101714.d4b22deHigh risk762026-06-10
0.8.10-dev.202606101514.1c52cedHigh risk762026-06-10
0.8.10-dev.202606101436.d73da44High risk762026-06-10
0.8.10-dev.202606101324.2fc90b3High risk762026-06-10
0.8.10-dev.202606101122.0de2affHigh risk762026-06-10
0.8.10-dev.202606100925.28c1cfbHigh risk762026-06-10
0.8.10-dev.202606100742.99a7fabHigh risk762026-06-10
0.8.10-dev.202606100317.c8b43c8High risk762026-06-10
0.8.10-dev.202606100110.1d2c8c4High risk762026-06-10
0.8.10-dev.202606092334.09948c8High risk762026-06-10
0.8.10-dev.202606092238.d04fd59High risk762026-06-10
0.8.10High risk762026-06-10
0.8.9-dev.202606092139.1f3b646High risk762026-06-10
0.8.9-dev.202606092047.e63da55High risk762026-06-10
0.8.10-staging.1High risk762026-06-10
0.8.9-dev.202606091946.122706eHigh risk762026-06-10
0.8.9-dev.202606091926.ebb2d62High risk762026-06-10
0.8.9-dev.202606091853.fbaa2aeHigh risk762026-06-10
0.8.9High risk762026-06-10
0.8.8-dev.202606091702.2771079High risk762026-06-10
0.8.9-staging.5High risk762026-06-10
0.8.8-dev.202606091516.3c27bebHigh risk762026-06-10
0.8.8-dev.202606091311.113d87fHigh risk762026-06-10
0.8.9-staging.4High risk762026-06-10
0.8.8-dev.202606090339.ad6ec5aHigh risk762026-06-10
0.8.8-dev.202606090318.74794feHigh risk762026-06-10
0.8.8-dev.202606090227.d9f1d29High risk762026-06-10
0.8.8-dev.202606090218.6bcb462High risk762026-06-10
0.8.8-dev.202606082331.c911d0cHigh risk762026-06-10
0.8.8-dev.202606090104.b75d235High risk762026-06-10
0.8.8-dev.202606082236.8dbacc9High risk762026-06-10
0.8.9-staging.3High risk762026-06-10
0.8.8-dev.202606082140.a5125feHigh risk762026-06-10
0.8.8-dev.202606082058.447e3b6High risk762026-06-10
0.8.8-dev.202606081950.5bd40e7High risk762026-06-10
0.8.8-dev.202606081859.f7bdc00High risk762026-06-10
0.8.8-dev.202606081714.5590368High risk762026-06-10
0.8.9-staging.2High risk762026-06-10
0.8.8-dev.202606081515.c77a9b6High risk762026-06-10
0.8.8-dev.202606081339.938c6ecHigh risk762026-06-10
0.8.9-staging.1High risk762026-06-10
0.8.8-dev.202606081143.f600053High risk762026-06-10
0.8.8-dev.202606080544.8b7fbffHigh risk762026-06-10
0.8.8-dev.202606080320.8b7fbffHigh risk762026-06-10
0.8.8-dev.202606080112.5f6d567High risk762026-06-10
0.8.8-dev.202606080009.0babb76High risk762026-06-10
0.8.8-dev.202606072328.6710d73High risk762026-06-10
0.8.8-dev.202606072131.4817a81High risk762026-06-10
0.8.8-dev.202606072033.0e97ff6High risk762026-06-10
0.8.8-dev.202606071935.547b6d2High risk762026-06-10
0.8.8-dev.202606071835.08695c1High risk762026-06-10
0.8.8-dev.202606071734.db66b83High risk762026-06-10
0.8.8-dev.202606071535.f449fc1High risk762026-06-10
0.8.8-dev.202606071441.cfe7f13High risk762026-06-10
0.8.8-dev.202606071338.2b9914eHigh risk762026-06-10
0.8.8-dev.202606071242.4ca7f3bHigh risk762026-06-10
0.8.8-dev.202606071138.c258385High risk762026-06-10
0.8.8-dev.202606071051.c258385High risk762026-06-10
0.8.8-dev.202606070049.ca91213High risk762026-06-10
0.8.8-dev.202606062128.ca91213High risk762026-06-10
0.8.8-dev.202606062031.571ee14High risk762026-06-10
0.8.8-dev.202606061935.99a472fHigh risk762026-06-10
0.8.8-dev.202606061835.dc283b1High risk762026-06-10
0.8.8-dev.202606061731.f1025b0High risk762026-06-10
0.8.8-dev.202606061714.60a1761High risk762026-06-10
0.8.8-dev.202606061701.9ee494cHigh risk762026-06-10
0.8.8-dev.202606061631.10cd5feHigh risk762026-06-10
0.8.8-dev.202606061533.1a66375High risk762026-06-10
0.8.8-dev.202606061135.a446a08High risk762026-06-10
0.8.8-dev.202606061043.373bc8fHigh risk762026-06-10
0.8.8-dev.202606060043.60454adHigh risk762026-06-10
0.8.8-dev.202606060901.61e1660High risk762026-06-10
0.8.8-dev.202606052332.17fc8eaHigh risk762026-06-10
0.8.8High risk762026-06-10
0.8.7-dev.202606052232.2ddc989High risk762026-06-10
0.8.7-dev.202606052220.6efc86dHigh risk762026-06-10
0.8.7-dev.202606052135.3e62c5aHigh risk762026-06-10
0.8.7-dev.202606052118.34cd356High risk762026-06-10
0.8.10-dev.202606100540.99a7fabHigh risk762026-06-10
0.8.7Review362026-06-03
0.8.6Review362026-05-29
0.8.4Review412026-05-27
0.8.5Review412026-05-27

Block this in CI

PkgRadar gates @vellumai/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vellumai/[email protected]