The main entrypoint actively collects cloud credentials, environment variables, and Kubernetes secret files, then sends them to an external host. This is a confirmed data-exfiltration surface.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entrypoint immediately posts to an external host.
index.jsView on unpkg · L5The entrypoint obtains AWS instance-metadata credentials and posts the collected information externally.
index.jsView on unpkg · L87The entrypoint copies all environment variables, recursively reads Kubernetes secrets, and posts them externally.
index.jsView on unpkg · L106The entrypoint copies all environment variables, recursively reads Kubernetes secrets, and posts them externally.
index.jsView on unpkg · L128The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L1This report applies to @hrmony/pladddform-cli@40.14.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entrypoint immediately posts to an external host.
index.jsView on unpkg · L5The entrypoint obtains AWS instance-metadata credentials and posts the collected information externally.
index.jsView on unpkg · L87The entrypoint copies all environment variables, recursively reads Kubernetes secrets, and posts them externally.
index.jsView on unpkg · L106The entrypoint copies all environment variables, recursively reads Kubernetes secrets, and posts them externally.
index.jsView on unpkg · L128The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L1