PkgRadar

npm · registry.npmjs.org

orcaq

DNS / OAST exfiltration: matched "dns.lookup"

Why PkgRadar flagged 1.1.7

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.lookup" · package/.output/server/node_modules/pg/lib/connection-parameters.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/.output/public/_nuxt/DtgJAz2h.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/.output/public/_nuxt/RFRrMFyH.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/.output/server/node_modules/consola/dist/index.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/.output/server/node_modules/consola/dist/chunks/prompt.mjs
mediumLarge Javascript Payload2608246 bytes · package/.output/public/_nuxt/CrwM3gOU.js
mediumLarge Javascript Payload4761294 bytes · package/.output/public/_nuxt/D7uoAo-G.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.8Low risk02026-06-03
1.1.7Review292026-05-26
1.1.5Review1862026-05-24
1.1.6Review1862026-05-24

Block this in CI

PkgRadar gates orcaq (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]