The main module steals cloud and local secret material on import. It transmits the material to an unrelated external host.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Importing the entrypoint immediately posts to an external host.
index.jsView on unpkg · L3It obtains AWS instance metadata, including IAM credential paths, and sends the collected object externally.
index.jsView on unpkg · L84It obtains AWS instance metadata, including IAM credential paths, and sends the collected object externally.
index.jsView on unpkg · L93It copies all environment variables and recursively reads Kubernetes secrets before posting them externally.
index.jsView on unpkg · L106It copies all environment variables and recursively reads Kubernetes secrets before posting them externally.
index.jsView on unpkg · L125This report applies to @hrmony/account-management@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Importing the entrypoint immediately posts to an external host.
index.jsView on unpkg · L3It obtains AWS instance metadata, including IAM credential paths, and sends the collected object externally.
index.jsView on unpkg · L84It obtains AWS instance metadata, including IAM credential paths, and sends the collected object externally.
index.jsView on unpkg · L93It copies all environment variables and recursively reads Kubernetes secrets before posting them externally.
index.jsView on unpkg · L106It copies all environment variables and recursively reads Kubernetes secrets before posting them externally.
index.jsView on unpkg · L125