npm · registry.npmjs.org
pnpm
DNS / OAST exfiltration: matched "dns.lookup"
Why PkgRadar flagged 10.34.1
| Severity | Signal | Evidence |
|---|---|---|
| high | DNS / OAST exfiltration | matched "dns.lookup" · package/dist/node_modules/@npmcli/agent/lib/dns.js |
| high | DNS / OAST exfiltration | matched "dns.lookup" · package/dist/node_modules/socks-proxy-agent/dist/index.js |
| high | DNS / OAST exfiltration | matched "dns.lookup" · package/dist/node_modules/make-fetch-happen/lib/options.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/node_modules/minipass-sized/package-lock.json |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/node_modules/.pnpm/lock.yaml |
| medium | Large Javascript Payload | 7883937 bytes · package/dist/pnpm.cjs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
11.6.0 | Low risk | 0 | 2026-06-11 |
10.34.3 | Low risk | 0 | 2026-06-11 |
10.34.2 | Low risk | 0 | 2026-06-10 |
11.5.3 | Low risk | 0 | 2026-06-10 |
11.5.2 | Low risk | 0 | 2026-06-05 |
11.5.1 | Low risk | 0 | 2026-06-02 |
11.5.0 | Low risk | 0 | 2026-05-29 |
10.34.1 | Review | 25 | 2026-05-28 |
11.4.0 | Review | 3 | 2026-05-27 |
10.34.0 | Review | 25 | 2026-05-27 |
11.2.2 | Review | 22 | 2026-05-24 |
11.3.0 | Review | 22 | 2026-05-24 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]