PkgRadar

npm · registry.npmjs.org

moonwork-openclaw

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.5.10

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-DT1k6JKx.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-BNNhQbkM.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-B0jP67OI.js
mediumNew Account With Lifecycle Hookpackage first published 41 day(s) ago, 9 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.5.10High risk1632026-06-16
2026.5.18-beta.1High risk1632026-06-16
2026.6.16-beta.1High risk1632026-06-16
2026.5.24-beta.1High risk1632026-06-10
2026.5.27-beta.1High risk1632026-06-10

Block this in CI

PkgRadar gates moonwork-openclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]