PkgRadar

PyPI · pypi.org

lnbits

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 1.5.5rc2

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · lnbits-1.5.5rc2/lnbits/core/services/notifications.py
highCredential File Packagedlnbits-1.5.5rc2/.npmrc · lnbits-1.5.5rc2/.npmrc
mediumRemote Payloadmatched "curl " · lnbits-1.5.5rc2/lnbits.sh
mediumRemote Payloadmatched "curl " · lnbits-1.5.5rc2/docker/regtest/docker-scripts.sh
mediumRemote Payloadmatched "wget " · lnbits-1.5.5rc2/lnbits/wallets/boltz_grpc_files/update.sh
mediumRemote Payloadmatched "wget " · lnbits-1.5.5rc2/lnbits/wallets/lnd_grpc_files/update.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.5rc2High risk612026-06-04

Block this in CI

PkgRadar gates lnbits (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi lnbits==1.5.5rc2