PkgRadar

npm · registry.npmjs.org

@wrongstack/cli

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.84.1

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.84.1Review112026-06-07
0.82.6Review112026-06-06
0.77.0Review112026-06-06
0.73.1Low risk02026-06-06
0.68.0Low risk02026-06-05
0.66.13Low risk02026-06-05
0.63.4Low risk02026-06-04
0.54.1Low risk02026-06-04
0.51.3Low risk02026-06-04
0.41.0Low risk02026-06-03
0.32.0Low risk02026-06-03
0.31.1Low risk02026-06-03
0.24.0Low risk02026-06-02
0.10.3Low risk02026-06-02
0.10.0Low risk02026-06-02
0.10.2Low risk02026-06-02
0.9.20Low risk02026-06-01
0.9.19Low risk02026-05-31
0.9.7Low risk02026-05-30
0.9.4Low risk02026-05-30
0.9.1Low risk02026-05-30
0.9.0Low risk02026-05-29
0.8.6Low risk02026-05-29
0.8.5Low risk02026-05-29
0.8.2Low risk02026-05-28
0.8.4Low risk02026-05-28
0.8.0Low risk02026-05-28
0.7.7Low risk02026-05-28
0.7.8Low risk02026-05-28
0.7.4Low risk02026-05-26
0.7.5Low risk02026-05-26
0.7.2Low risk02026-05-26
0.7.0Low risk02026-05-25
0.6.7Low risk02026-05-24
0.6.6Low risk02026-05-24
0.6.5Low risk02026-05-24

Block this in CI

PkgRadar gates @wrongstack/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @wrongstack/[email protected]