The main module harvests cloud metadata, environment variables, and Kubernetes secret files, then sends them to an external host. The behavior activates on module import.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Importing the entrypoint immediately posts to an external exporter URL.
index.jsView on unpkg · L5The entrypoint requests AWS instance metadata, including IAM role credentials and instance user data, then posts the collected object.
index.jsView on unpkg · L82The entrypoint requests AWS instance metadata, including IAM role credentials and instance user data, then posts the collected object.
index.jsView on unpkg · L94The entrypoint copies all process environment variables and recursively reads Kubernetes secrets.
index.jsView on unpkg · L104The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L2This report applies to @hrmony/benefitverwaltung@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Importing the entrypoint immediately posts to an external exporter URL.
index.jsView on unpkg · L5The entrypoint requests AWS instance metadata, including IAM role credentials and instance user data, then posts the collected object.
index.jsView on unpkg · L82The entrypoint requests AWS instance metadata, including IAM role credentials and instance user data, then posts the collected object.
index.jsView on unpkg · L94The entrypoint copies all process environment variables and recursively reads Kubernetes secrets.
index.jsView on unpkg · L104The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L2