PkgRadar

npm · registry.npmjs.org

agentiqa

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 1.1.11-staging.f26ff3c

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/cli.js
highInstall Lifecycle Suppresses Failurepostinstall="npx playwright install chromium 2>/dev/null || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.11-staging.f26ff3cHigh risk492026-06-14
1.1.10High risk492026-06-14
1.1.10-staging.87183edHigh risk492026-06-14
1.1.10-staging.8116b68High risk492026-06-12
1.1.10-staging.46da459High risk492026-06-12
1.1.10-staging.c65303dHigh risk492026-06-12
1.1.9High risk702026-06-11
1.1.10-staging.01e8f0cHigh risk702026-06-11
1.1.9-staging.ff161f5High risk702026-06-11
1.1.9-staging.1f2fb16High risk702026-06-11
1.1.9-staging.f90a478High risk702026-06-10
1.1.9-staging.45d4e5dHigh risk702026-06-10
1.1.9-staging.e1d2b4eHigh risk702026-06-10
1.1.8High risk702026-06-10
1.1.9-staging.5fadedfHigh risk702026-06-10
1.1.9-staging.ad6d2f9High risk702026-06-10
1.1.9-staging.756ee97High risk702026-06-10
1.1.9-staging.4091ff1High risk702026-06-10
1.1.9-staging.d1964abHigh risk702026-06-10
1.1.7-staging.eb583eeHigh risk702026-06-10
1.1.7-staging.fc9ac4fHigh risk702026-06-10
1.1.7-staging.7150afdHigh risk702026-06-10
1.1.7-staging.4883a7eHigh risk702026-06-10
1.1.9-staging.473d4a3High risk702026-06-10
1.1.7-staging.9720d22High risk702026-06-10
1.1.9-staging.743a7c7High risk702026-06-10
1.1.6-staging.f96be6aHigh risk302026-06-10
1.1.7High risk302026-06-10

Block this in CI

PkgRadar gates agentiqa (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]