PkgRadar

npm · registry.npmjs.org

cue-ai

Webhook Exfil Endpoint: matched "requestbin.com"

Why PkgRadar flagged 0.9.3

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "requestbin.com" · package/resources/skills/skills/gstack/browse/src/content-security.ts
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · package/resources/skills/skills/gstack/browse/src/content-security.ts
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-media/create-music.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-edit/enhance-image.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-media/generate-image.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-media/generate-video.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-media/image-to-video.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-edit/lipsync.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-media/upload.sh
mediumRemote Payloadmatched "curl " · package/resources/skills/skills/media/core-edit/video-effects.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/commands/import-profile.ts
mediumNew Account With Lifecycle Hookpackage first published 20 day(s) ago, 10 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.3High risk1822026-06-12
0.9.2High risk1272026-06-10
0.9.1High risk1272026-06-10
0.9.0High risk1142026-06-10
0.7.0Review1742026-05-24
0.5.0Review1742026-05-24
0.6.0Review1742026-05-24

Related campaigns

Block this in CI

PkgRadar gates cue-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]