The import entrypoint harvests cloud and local secrets and sends them to an external host. This is an active data-exfiltration payload.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4It collects AWS instance identity, user data, and instance-role credentials before sending the collected data.
index.jsView on unpkg · L87It copies all environment variables and recursively reads Kubernetes secret files, then posts them externally.
index.jsView on unpkg · L111It copies all environment variables and recursively reads Kubernetes secret files, then posts them externally.
index.jsView on unpkg · L128Package metadata designates index.js as the import entrypoint.
package.jsonView on unpkg · L1This report applies to @hrmony/hyper-json-builder@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4It collects AWS instance identity, user data, and instance-role credentials before sending the collected data.
index.jsView on unpkg · L87It copies all environment variables and recursively reads Kubernetes secret files, then posts them externally.
index.jsView on unpkg · L111It copies all environment variables and recursively reads Kubernetes secret files, then posts them externally.
index.jsView on unpkg · L128Package metadata designates index.js as the import entrypoint.
package.jsonView on unpkg · L1