PkgRadar

npm · registry.npmjs.org

alvin-bot

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 5.61.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/bin/cli.js
mediumRemote Payloadmatched "curl " · package/bin/cli.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/services/preflight.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/web/setup-api.js
mediumRemote Payloadmatched "curl " · package/dist/providers/tool-executor.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.61.0High risk682026-06-17
5.60.0High risk992026-06-16
5.59.0High risk802026-06-16
5.58.0High risk812026-06-15
5.57.0High risk562026-06-15
5.56.0High risk602026-06-14
5.55.0High risk392026-06-14
5.54.0High risk392026-06-14
5.53.0High risk682026-06-14
5.52.0High risk512026-06-14
5.51.0High risk442026-06-14
5.50.0High risk812026-06-14
5.49.0High risk482026-06-12
5.48.2High risk692026-06-11
5.48.1High risk602026-06-11
5.48.0High risk602026-06-11
5.47.0High risk682026-06-11
5.46.0High risk482026-06-10
5.45.1High risk562026-06-10
5.45.0High risk602026-06-10
5.24.4High risk1502026-06-10
5.44.1High risk742026-06-10
5.44.0High risk562026-06-10
5.43.2High risk622026-06-10
5.43.1High risk512026-06-10
5.43.0High risk512026-06-10
5.42.1High risk872026-06-10
5.42.0High risk562026-06-10
5.41.0High risk392026-06-10
5.40.0High risk392026-06-10
5.39.0High risk442026-06-10
5.37.1Review222026-06-01
5.37.2Review342026-06-01
5.37.0Review202026-06-01
5.36.0Review112026-06-01
5.35.0Review112026-06-01
5.34.0Review172026-05-29
5.32.0Review342026-05-29
5.33.0Review222026-05-29
5.24.5Review112026-05-28
5.24.6Review152026-05-28
5.24.2Review802026-05-25
5.24.3Review802026-05-25
5.22.5Review82026-05-25
5.22.3Review122026-05-25
5.22.4Review122026-05-25
5.22.1Review242026-05-24
5.22.0Review242026-05-24
5.20.2Review542026-05-24
5.21.0Review242026-05-24
5.20.1Review242026-05-24
5.20.0Review542026-05-24
5.19.0Review242026-05-24
5.18.0Review242026-05-24
5.17.1Review242026-05-24
5.17.2Review242026-05-24

Block this in CI

PkgRadar gates alvin-bot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]