PkgRadar

npm · registry.npmjs.org

openclaw

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.6.8-beta.2

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-C66-RP37.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-BjMF75Lf.js
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/i18n-C0k1rM_n.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-S4rLRTkN.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-install-env-CSqfL5Dl.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-managed-root-DLQZyFtc.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.8-beta.2High risk622026-06-16
2026.6.8-beta.1High risk622026-06-14
2026.6.7-beta.1High risk622026-06-13
2026.6.6High risk622026-06-12
2026.6.6-beta.2High risk622026-06-12
2026.6.5Review602026-06-09
2026.6.5-beta.6Review602026-06-09
2026.6.5-beta.5Review602026-06-08
2026.6.5-beta.3Review602026-06-08
2026.6.5-beta.2Review602026-06-07
2026.6.5-beta.1Review602026-06-06
2026.6.2-beta.1Review602026-06-04
2026.6.1Review602026-06-03
2026.6.1-beta.3Review602026-06-03
2026.6.1-beta.2Review602026-06-02
2026.6.1-beta.1Review602026-06-01
2026.5.31-beta.4Review602026-06-01
2026.5.31-beta.3Review602026-05-31
2026.5.31-beta.2Review602026-05-31
2026.5.31-beta.1Review602026-05-31
2026.5.30-beta.1Review752026-05-31
2026.5.28Review752026-05-30
2026.5.28-beta.4Review752026-05-29
2026.5.28-beta.3Review752026-05-29
2026.5.28-beta.1Review912026-05-29
2026.5.27Review1072026-05-28
2026.5.27-beta.1Review1072026-05-28
2026.5.26Review902026-05-27
2026.5.26-beta.2Review902026-05-27
2026.5.26-beta.1Review902026-05-27
2026.5.25-beta.1Review902026-05-26
2026.5.24-beta.2Review2602026-05-25
2026.5.24-beta.1Review2602026-05-24
2026.5.22-beta.1Review2802026-05-24
2026.5.22Review2802026-05-24

Block this in CI

PkgRadar gates openclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]