PkgRadar

npm · registry.npmjs.org

llm-fw

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 0.1.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · package/dist/dashboard/server.js
highWebhook Exfil Endpointmatched "webhook.site" · package/dist/detection/urlHeuristic.js
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · package/dist/detection/urlHeuristic.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0High risk852026-06-09

Block this in CI

PkgRadar gates llm-fw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]