PkgRadar

npm · registry.npmjs.org

sz_claw

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 0.0.6

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/extensions/voice-call/index.js
highCredential File Packagedpackage/dist/extensions/telegram/node_modules/bottleneck/.env · package/dist/extensions/telegram/node_modules/bottleneck/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.6High risk852026-06-10
0.0.7High risk852026-06-10

Related campaigns

Block this in CI

PkgRadar gates sz_claw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]