PkgRadar

npm · registry.npmjs.org

loopuman-production

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 4.0.0

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/services/admin-alerts.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/scheduler_competition_addition.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/scheduler.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/backups-20260209/whatsapp-bot.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/backups/20260209/whatsapp-bot.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/tmp/whatsapp-bot.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/whatsapp-bot.js
mediumRemote Payloadmatched "curl " · package/deploy-seo.sh
mediumRemote Payloadmatched "curl " · package/test-everything.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.0Review1142026-06-09
4.0.2Review1502026-06-09

Block this in CI

PkgRadar gates loopuman-production (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]