PkgRadar

npm · registry.npmjs.org

bheeshma

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 2.1.1

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · package/src/patterns/malwareSignatures.js
highDNS / OAST exfiltrationmatched "canarytokens.com" · package/src/hooks/dnsHook.js
highInstall Lifecycle Remote Or Execpostinstall="node -e \"if(process.env.npm_config_global){console.log('');console.log(' bheeshma v'+require('./package.json').version+' — strace for npm packages');console.log(' Runtime dependency behavior monitor for Node.js');console.log('');console.log(' Star us on GitHub if bheeshma saved your project:');console.log(' https://github.com/bb1nfosec/bheeshma');console.log('');}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.1High risk1152026-06-10
3.0.0High risk802026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Related campaigns

Block this in CI

PkgRadar gates bheeshma (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]