PkgRadar

npm · registry.npmjs.org

pnpm

DNS / OAST exfiltration: matched "dns.lookup"

Why PkgRadar flagged 10.34.1

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/node_modules/@npmcli/agent/lib/dns.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/node_modules/socks-proxy-agent/dist/index.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/node_modules/make-fetch-happen/lib/options.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/node_modules/minipass-sized/package-lock.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/node_modules/.pnpm/lock.yaml
mediumLarge Javascript Payload7883937 bytes · package/dist/pnpm.cjs

Scanned versions

VersionVerdictScoreScanned (UTC)
11.6.0Low risk02026-06-11
10.34.3Low risk02026-06-11
10.34.2Low risk02026-06-10
11.5.3Low risk02026-06-10
11.5.2Low risk02026-06-05
11.5.1Low risk02026-06-02
11.5.0Low risk02026-05-29
10.34.1Review252026-05-28
11.4.0Review32026-05-27
10.34.0Review252026-05-27
11.2.2Review222026-05-24
11.3.0Review222026-05-24

Block this in CI

PkgRadar gates pnpm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]