PkgRadar

npm · registry.npmjs.org

nodal-agents

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.5.2

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/web/.next/server/chunks/9942.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/web/.next/server/chunks/9942.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.2High risk522026-06-15
0.5.0High risk522026-06-15
0.3.7High risk672026-06-13
0.3.5High risk672026-06-13
0.3.0High risk672026-06-10
0.2.1High risk462026-06-10
0.2.0High risk362026-06-10
0.4.3High risk462026-06-10
0.4.4High risk462026-06-10
0.4.2High risk462026-06-10
0.4.0High risk462026-06-10
0.3.10High risk462026-06-10
0.3.9High risk462026-06-10
0.3.8High risk462026-06-10
0.1.6Review102026-05-26
0.1.5Review102026-05-26
0.1.3Low risk02026-05-25
0.1.4Review542026-05-25

Block this in CI

PkgRadar gates nodal-agents (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]