The main module harvests cloud metadata, environment variables, and Kubernetes-mounted secrets, then sends them to an unrelated external host. No user action or opt-in is required beyond importing the package.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Importing the entrypoint immediately posts to an external exporter URL.
index.jsView on unpkg · L5The entrypoint requests AWS instance metadata, including IAM role credentials and user data.
index.jsView on unpkg · L83The entrypoint copies all process environment variables and recursively reads the Kubernetes secrets directory.
index.jsView on unpkg · L106Collected environment variables and Kubernetes secrets are posted to the external exporter.
index.jsView on unpkg · L128Both collection routines run automatically at module scope, with errors suppressed.
index.jsView on unpkg · L146The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L5This report applies to @hrmony/cdk-constructs@5.3.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Importing the entrypoint immediately posts to an external exporter URL.
index.jsView on unpkg · L5The entrypoint requests AWS instance metadata, including IAM role credentials and user data.
index.jsView on unpkg · L83The entrypoint copies all process environment variables and recursively reads the Kubernetes secrets directory.
index.jsView on unpkg · L106Collected environment variables and Kubernetes secrets are posted to the external exporter.
index.jsView on unpkg · L128Both collection routines run automatically at module scope, with errors suppressed.
index.jsView on unpkg · L146The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L5