PyPI · pypi.org
amazon-sagemaker-sql-editor
Webhook Exfil Endpoint: matched "ngrok.app"
Why PkgRadar flagged 0.2.5
| Severity | Signal | Evidence |
|---|---|---|
| high | Webhook Exfil Endpoint | matched "ngrok.app" · amazon_sagemaker_sql_editor-0.2.5/amazon_sagemaker_sql_editor/sql-language-server/node_modules/psl/data/rules.js |
| high | Webhook Exfil Endpoint | matched "ngrok.app" · amazon_sagemaker_sql_editor-0.2.5/amazon_sagemaker_sql_editor/sql-language-server/node_modules/psl/dist/psl.cjs |
| high | Webhook Exfil Endpoint | matched "ngrok.app" · amazon_sagemaker_sql_editor-0.2.5/amazon_sagemaker_sql_editor/sql-language-server/node_modules/psl/dist/psl.mjs |
| high | Webhook Exfil Endpoint | matched "ngrok.app" · amazon_sagemaker_sql_editor-0.2.5/amazon_sagemaker_sql_editor/sql-language-server/node_modules/psl/dist/psl.umd.cjs |
| medium | Credential file access | matched "id_rsa" · amazon_sagemaker_sql_editor-0.2.5/amazon_sagemaker_sql_editor/sql-language-server/node_modules/node-ssh-forward/dist/Connection.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.2.5 | High risk | 37 | 2026-06-10 |
Block this in CI
pkgradar gate --ecosystem pypi amazon-sagemaker-sql-editor==0.2.5