PkgRadar

npm · registry.npmjs.org

remoteclaw

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.8.0-next.20260603101202.7419541

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/plugin-sdk/compat.js
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/plugin-sdk/index.js
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/plugin-sdk/telegram.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/extensions/voice-call/src/webhook-security.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/compat.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/index.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/setup-helpers-BtRTZkJZ.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/setup-helpers-CQPGtU2X.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/telegram.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-target-BfKmGkYG.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-target-C-YFVXgH.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.0-next.20260603101202.7419541Review732026-06-03
0.8.0-next.20260602140056.f5aa883Review732026-06-02
0.8.0-next.20260602150737.b87a5deReview732026-06-02
0.8.0-next.20260601173216.d202b54Review732026-06-01
0.8.0-next.20260517114349.3c200feReview732026-06-01
0.8.0-next.20260601113131.26cd3f6Review732026-06-01

Block this in CI

PkgRadar gates remoteclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]