The main module harvests cloud and local secrets and sends them to an external endpoint. No user action or configuration gate protects this behavior.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4The entry point immediately posts to an external host when imported.
index.jsView on unpkg · L5It queries AWS instance metadata, including IAM role credentials and user data.
index.jsView on unpkg · L83It collects all environment variables and recursively reads Kubernetes secret files.
index.jsView on unpkg · L104Collected environment variables and Kubernetes secrets are posted to the external host.
index.jsView on unpkg · L130Both cloud and local collection routines run automatically at module load.
index.jsView on unpkg · L146The package declares index.js as its main entry point.
package.jsonView on unpkg · L2This report applies to @hrmony/interfaces@0.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4The entry point immediately posts to an external host when imported.
index.jsView on unpkg · L5It queries AWS instance metadata, including IAM role credentials and user data.
index.jsView on unpkg · L83It collects all environment variables and recursively reads Kubernetes secret files.
index.jsView on unpkg · L104Collected environment variables and Kubernetes secrets are posted to the external host.
index.jsView on unpkg · L130Both cloud and local collection routines run automatically at module load.
index.jsView on unpkg · L146The package declares index.js as its main entry point.
package.jsonView on unpkg · L2