PkgRadar

npm · registry.npmjs.org

ciphernest

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 0.8.6

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · package/packages/mcp-gateway/dist/index.js
highDNS / OAST exfiltrationmatched "canarytokens.com" · package/packages/mcp-gateway/dist/index.js
highDNS / OAST exfiltrationmatched "canarytokens.com" · package/packages/mcp-gateway/src/index.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.6High risk1252026-06-05
0.8.4High risk1252026-06-05
0.8.0High risk1252026-06-05
0.5.0Review302026-06-04
0.7.0Low risk02026-06-04

Block this in CI

PkgRadar gates ciphernest (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]