npm · registry.npmjs.org
bheeshma
Webhook Exfil Endpoint: matched "webhook.site"
Why PkgRadar flagged 2.1.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Webhook Exfil Endpoint | matched "webhook.site" · package/src/patterns/malwareSignatures.js |
| high | DNS / OAST exfiltration | matched "canarytokens.com" · package/src/hooks/dnsHook.js |
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"if(process.env.npm_config_global){console.log('');console.log(' bheeshma v'+require('./package.json').version+' — strace for npm packages');console.log(' Runtime dependency behavior monitor for Node.js');console.log('');console.log(' Star us on GitHub if bheeshma saved your project:');console.log(' https://github.com/bb1nfosec/bheeshma');console.log('');}\"" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.1.1 | High risk | 115 | 2026-06-10 |
3.0.0 | High risk | 80 | 2026-06-10 |
Campaign attribution
Related campaigns
- bb1nfosec — 2 releases, max score 115
Block this in CI
pkgradar gate --ecosystem npm [email protected]