PkgRadar

npm · registry.npmjs.org

sealclaw

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.6.26-beta.6

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-CVQVrFjD.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-BHZ-DWpR.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-B6W_Vq0P.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.26-beta.6High risk1172026-06-13
2026.6.26-beta.5High risk1682026-06-12
2026.6.26-beta.4High risk1682026-06-11
2026.6.26-beta.3High risk1172026-06-11
2026.6.26-beta.1High risk1172026-06-11
2026.6.26-beta.2High risk1172026-06-11
2026.6.17-beta.6High risk1172026-06-10
2026.6.17-beta.12High risk1172026-06-10
2026.6.17-beta.11High risk1172026-06-10
2026.6.17-beta.10High risk1172026-06-10
2026.6.17-beta.8High risk1172026-06-10
2026.6.17-beta.9High risk1172026-06-10
2026.6.17-beta.5High risk1172026-06-10
2026.6.17-beta.4High risk1172026-06-10
2026.6.25High risk1172026-06-10
2026.6.24High risk1172026-06-10
2026.6.23High risk1172026-06-10
2026.6.23-beta.1High risk1172026-06-10
2026.6.22High risk1172026-06-10
2026.6.22-beta.10High risk1172026-06-10
2026.6.22-beta.9High risk1172026-06-10
2026.6.22-beta.8High risk1172026-06-10
2026.6.22-beta.7High risk1172026-06-10
2026.6.22-beta.5High risk1172026-06-10
2026.6.22-beta.6High risk1172026-06-10
2026.6.22-beta.4High risk1172026-06-10
2026.6.22-beta.3High risk1172026-06-10
2026.6.22-beta.2High risk1172026-06-10
2026.6.22-beta.1High risk1172026-06-10
2026.6.21High risk1172026-06-10
2026.6.20-beta.2High risk1172026-06-10
2026.6.20High risk1172026-06-10
2026.6.20-beta.1High risk1172026-06-10
2026.6.19-beta.1High risk1172026-06-10
2026.6.19High risk1172026-06-10
2026.6.18High risk1172026-06-10
2026.6.17-beta.31High risk1172026-06-10
2026.6.17-beta.29High risk1172026-06-10
2026.6.17-beta.30High risk1172026-06-10
2026.6.17-beta.28High risk1172026-06-10
2026.6.17-beta.27High risk1172026-06-10
2026.6.17-beta.26High risk1172026-06-10
2026.6.17-beta.25High risk1172026-06-10
2026.6.17-beta.24High risk1172026-06-10
2026.6.17-beta.23High risk1172026-06-10
2026.6.17-beta.22High risk1172026-06-10
2026.6.17-beta.21High risk1172026-06-10
2026.6.17-beta.20High risk1172026-06-10
2026.6.17-beta.19High risk1172026-06-10
2026.6.17-beta.18High risk1172026-06-10
2026.6.17-beta.17High risk1172026-06-10
2026.6.17-beta.16High risk1172026-06-10
2026.6.17-beta.15High risk1172026-06-10
2026.6.17-beta.14High risk1172026-06-10
2026.6.14High risk1172026-06-10
2026.6.15-beta.1High risk1172026-06-10
2026.6.16-beta.1High risk1172026-06-10
2026.6.13-beta.3High risk1172026-06-10
2026.6.13-beta.5High risk1172026-06-10
2026.6.13-beta.2High risk1172026-06-10
2026.6.13High risk1172026-06-10
2026.6.13-beta.4High risk1172026-06-10
2026.6.13-beta.1High risk1172026-06-10
2026.6.12-beta.2High risk1172026-06-10
2026.6.16High risk1172026-06-10
2026.6.15High risk1172026-06-10
2026.6.17-beta.13High risk1172026-06-10

Block this in CI

PkgRadar gates sealclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]