PkgRadar

npm · registry.npmjs.org

novu

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2.8.1-rc.13

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/src/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.1-rc.13High risk222026-06-13
2.14.0High risk222026-06-12
2.13.0High risk222026-06-12
2.12.0High risk222026-06-10
2.12.0-rc.0High risk222026-06-10
2.11.0High risk222026-06-10
2.8.1-rc.12High risk222026-06-10
2.8.1-rc.11High risk222026-06-10
2.8.1-rc.10High risk202026-06-10
2.8.1-rc.9High risk202026-06-10
2.8.1-rc.8High risk202026-06-10
2.10.0High risk222026-06-10
2.10.0-rc.3High risk222026-06-10
2.10.0-rc.2High risk222026-06-10
2.10.0-rc.1High risk222026-06-10
2.10.0-rc.0High risk222026-06-10
2.9.2High risk222026-06-10
2.9.1High risk222026-06-10
2.9.0High risk222026-06-10
2.9.0-beta.1High risk222026-06-10
2.9.0-beta.0High risk222026-06-10
2.8.1-rc.16High risk222026-06-10
2.8.1-rc.15High risk222026-06-10
2.8.1-rc.14High risk222026-06-10

Block this in CI

PkgRadar gates novu (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]