npm · registry.npmjs.org
sic-security
DNS / OAST exfiltration: matched "burpcollaborator.net"
Why PkgRadar flagged 6.0.1
| Severity | Signal | Evidence |
|---|---|---|
| high | DNS / OAST exfiltration | matched "burpcollaborator.net" · package/hexstrike_server.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
6.0.1 | High risk | 30 | 2026-06-06 |
6.0.0 | High risk | 30 | 2026-06-06 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]