PkgRadar

npm · registry.npmjs.org

fdb2

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 1.0.24

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/node_modules/.pnpm/[email protected]/node_modules/psl/dist/psl.cjs
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/node_modules/.pnpm/[email protected]/node_modules/psl/dist/psl.umd.cjs
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/node_modules/.pnpm/[email protected]/node_modules/psl/data/rules.js
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/node_modules/.pnpm/[email protected]/node_modules/psl/dist/psl.mjs
highCredential File Packagedpackage/bin/docker/.env · package/bin/docker/.env
mediumRemote Payloadmatched "curl " · package/dist/node_modules/.pnpm/[email protected]/node_modules/better-sqlite3/deps/download.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.24High risk1022026-06-03
1.0.22High risk352026-06-03
1.0.23High risk352026-06-03

Block this in CI

PkgRadar gates fdb2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]