PkgRadar

npm · registry.npmjs.org

webtorrent

DNS / OAST exfiltration: matched "dns.resolve"

Why PkgRadar flagged 3.0.12

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.resolve" · package/dist/webtorrent.chromeapp.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.5Low risk02026-05-30
3.0.16Low risk02026-05-29
3.0.15Low risk02026-05-29
3.0.14Low risk02026-05-28
3.0.12Review92026-05-27
3.0.13Review92026-05-27
3.0.10Review92026-05-27
3.0.11Review92026-05-27
3.0.6Review92026-05-26
3.0.5Review92026-05-25
3.0.4Review92026-05-25
3.0.2Review92026-05-25
3.0.3Review92026-05-25
3.0.1Review92026-05-25
3.0.0Review302026-05-24

Block this in CI

PkgRadar gates webtorrent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]