npm · registry.npmjs.org
buddy-bot
DNS / OAST exfiltration: matched "dns.lookup"
Why PkgRadar flagged 0.9.19
| Severity | Signal | Evidence |
|---|---|---|
| high | DNS / OAST exfiltration | matched "dns.lookup" · package/dist/chunk-qpftbbt7.js |
| high | DNS / OAST exfiltration | matched "dns.lookup" · package/dist/chunk-w3fxbsp0.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/bin/cli.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.9.19 | Review | 27 | 2026-05-25 |
0.9.20 | Review | 29 | 2026-05-25 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]