PkgRadar

npm · registry.npmjs.org

patchwork-os

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 0.2.0-beta.12.canary.230

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/config.js
highDNS / OAST exfiltrationmatched "dig $DOMAIN)\"\n echo \" - Port 80 blocked\"\n echo \" Re-run manually: certbot --nginx -d $DOMAIN\"\n fi\nfi\n\n# ── 11. Start service ─────────────────────────────────────────────────────────\nsection \"Starting service\"\n\nsystemctl restart \"$SERVICE_NAME\"\n\necho -n \"Waiting for bridge...\"\nfor i in $(" · package/deploy/bootstrap-new-vps.sh
highInstall Lifecycle Suppresses Failurepostinstall="node scripts/postinstall.mjs || true" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/recipeRoutes.js
mediumRemote Payloadmatched "curl " · package/deploy/bootstrap-vps.sh
mediumRemote Payloadmatched "curl " · package/deploy/install-vps-service.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0-beta.12.canary.230High risk392026-06-16
0.2.0-beta.12.canary.229High risk392026-06-16
0.2.0-beta.12.canary.228High risk392026-06-16
0.2.0-beta.12.canary.227High risk392026-06-16
0.2.0-beta.12.canary.226High risk392026-06-16
0.2.0-beta.12.canary.224High risk392026-06-16
0.2.0-beta.12.canary.225High risk392026-06-16
0.2.0-beta.12.canary.223High risk392026-06-16
0.2.0-beta.12.canary.222High risk392026-06-13
0.2.0-beta.12.canary.221High risk392026-06-13
0.2.0-beta.12.canary.220High risk392026-06-13
0.2.0-beta.12.canary.219High risk392026-06-10
0.2.0-beta.12.canary.218High risk392026-06-10
0.2.0-beta.12High risk392026-06-10
0.2.0-beta.11.canary.215High risk392026-06-10
0.2.0-beta.11.canary.216High risk392026-06-10
0.2.0-beta.11.canary.213High risk392026-06-10
0.2.0-beta.11.canary.212High risk392026-06-10
0.2.0-beta.11.canary.211High risk392026-06-10
0.2.0-beta.11.canary.210High risk392026-06-10
0.2.0-beta.11.canary.209High risk392026-06-10
0.2.0-beta.11.canary.206High risk392026-06-10
0.2.0-beta.11.canary.207High risk392026-06-10
0.2.0-beta.11.canary.205High risk392026-06-10
0.2.0-beta.11.canary.203Review392026-06-09
0.2.0-beta.11.canary.201Review392026-06-09
0.2.0-beta.11.canary.202Review392026-06-09
0.2.0-beta.11.canary.199Review392026-06-09
0.2.0-beta.11.canary.200Review392026-06-09
0.2.0-beta.11.canary.197Review392026-06-09
0.2.0-beta.11.canary.196Review392026-06-09
0.2.0-beta.11.canary.194Review392026-06-09
0.2.0-beta.11.canary.193Review392026-06-09
0.2.0-beta.11.canary.192Review392026-06-09
0.2.0-beta.11.canary.191Review392026-06-09
0.2.0-beta.11.canary.190Review392026-06-09
0.2.0-beta.11.canary.189Review392026-06-08
0.2.0-beta.11.canary.188Review392026-06-07
0.2.0-beta.11.canary.187Review392026-06-07
0.2.0-beta.11.canary.186Review392026-06-07
0.2.0-beta.11.canary.185Review392026-06-07
0.2.0-beta.11.canary.184Review392026-06-07
0.2.0-beta.11.canary.183Review392026-06-07
0.2.0-beta.11.canary.182Review392026-06-07
0.2.0-beta.11.canary.181Review392026-06-07
0.2.0-beta.11.canary.180Review392026-06-07
0.2.0-beta.11.canary.179Review392026-06-07
0.2.0-beta.11.canary.178Review392026-06-07
0.2.0-beta.11.canary.177Review392026-06-07
0.2.0-beta.11.canary.176Review392026-06-07
0.2.0-beta.11.canary.175Review392026-06-07
0.2.0-beta.11.canary.173Review392026-06-07
0.2.0-beta.11.canary.174Review392026-06-07
0.2.0-beta.11.canary.172Review392026-06-07
0.2.0-beta.11.canary.171Review392026-06-06
0.2.0-beta.11Review392026-06-06
0.2.0-beta.10.canary.169Review392026-06-06
0.2.0-beta.10.canary.168Review392026-06-06
0.2.0-beta.10.canary.167Review392026-06-06
0.2.0-beta.10.canary.166Review392026-06-06
0.2.0-beta.10.canary.164Review392026-06-05
0.2.0-beta.10.canary.165Review392026-06-05
0.2.0-beta.10.canary.162Review392026-06-05
0.2.0-beta.10.canary.161Review392026-06-05
0.2.0-beta.10.canary.160Review392026-06-05
0.2.0-beta.10.canary.158Review392026-06-05
0.2.0-beta.10.canary.159Review392026-06-05
0.2.0-beta.10.canary.156Review392026-06-05
0.2.0-beta.10.canary.157Review392026-06-05
0.2.0-beta.10.canary.155Review392026-06-05
0.2.0-beta.10.canary.153Review392026-06-05
0.2.0-beta.10.canary.152Review392026-06-05
0.2.0-beta.10.canary.151Review392026-06-05
0.2.0-beta.10.canary.150Review392026-06-05
0.2.0-beta.10.canary.149Review392026-06-05
0.2.0-beta.10.canary.148Review392026-06-05
0.2.0-beta.10.canary.147Review392026-06-05
0.2.0-beta.10.canary.146Review392026-06-05
0.2.0-beta.10.canary.144Review392026-06-05
0.2.0-beta.10.canary.145Review392026-06-05
0.2.0-beta.10.canary.143Review392026-06-05
0.2.0-beta.10.canary.142Review392026-06-05
0.2.0-beta.10.canary.140Review392026-06-04
0.2.0-beta.10.canary.141Review392026-06-04
0.2.0-beta.10.canary.128Review392026-06-04
0.2.0-beta.10.canary.129Review392026-06-04
0.2.0-beta.10.canary.126Review392026-06-04
0.2.0-beta.10.canary.127Review392026-06-04
0.2.0-beta.10.canary.124Review392026-06-04
0.2.0-beta.10.canary.125Review392026-06-04
0.2.0-beta.10.canary.123Review392026-06-04
0.2.0-beta.10.canary.122Review392026-06-04
0.2.0-beta.10.canary.121Review392026-06-04
0.2.0-beta.10.canary.120Review392026-06-04
0.2.0-beta.10.canary.118Review392026-06-03
0.2.0-beta.10.canary.119Review392026-06-03
0.2.0-beta.10.canary.111Review392026-06-03
0.2.0-beta.10.canary.112Review392026-06-03
0.2.0-beta.10.canary.106Review392026-06-03
0.2.0-beta.10.canary.107Review392026-06-03
0.2.0-beta.10.canary.103Review392026-06-03
0.2.0-beta.10.canary.101Review392026-06-03
0.2.0-beta.10.canary.100Review392026-06-03
0.2.0-beta.10.canary.99Review392026-06-03
0.2.0-beta.10.canary.98Review392026-06-03
0.2.0-beta.10.canary.97Review392026-06-02
0.2.0-beta.10.canary.96Review392026-06-02
0.2.0-beta.10.canary.95Review392026-06-02
0.2.0-beta.10Review392026-06-02
0.2.0-beta.9.canary.92Review392026-06-02
0.2.0-beta.9.canary.93Review392026-06-02
0.2.0-beta.9.canary.91Review392026-06-02
0.2.0-beta.9.canary.90Review392026-06-02
0.2.0-beta.9.canary.89Review392026-05-31
0.2.0-beta.9.canary.88Review392026-05-31
0.2.0-beta.9.canary.86Review392026-05-29
0.2.0-beta.9Review392026-05-29
0.2.0-beta.9.canary.84Review392026-05-29
0.2.0-beta.8.canary.77Review672026-05-27
0.2.0-beta.8.canary.78Review672026-05-27
0.2.0-beta.8.canary.69Review672026-05-26
0.2.0-beta.8.canary.70Review672026-05-26
0.2.0-beta.8.canary.61Review2242026-05-25
0.2.0-beta.8.canary.60Review1842026-05-25
0.2.0-beta.8.canary.59Review1842026-05-25
0.2.0-beta.8.canary.57Review2652026-05-24
0.2.0-beta.7.canary.55Review2652026-05-24
0.2.0-beta.7.canary.54Review2652026-05-24
0.2.0-beta.8Review2652026-05-24
0.2.0-beta.7.canary.52Review2652026-05-24
0.2.0-beta.7.canary.51Review2652026-05-24
0.2.0-beta.7Review2652026-05-24

Block this in CI

PkgRadar gates patchwork-os (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]