The package entrypoint harvests cloud metadata, process environment variables, and Kubernetes secrets, then transmits them to an external host. No user action or opt-in gate is present in the entrypoint.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint sends a POST request to an external exporter as it loads.
index.jsView on unpkg · L5The code queries AWS instance metadata, including IAM role credentials and instance credentials.
index.jsView on unpkg · L82Collected AWS information is POSTed to the external exporter.
index.jsView on unpkg · L94The code copies all environment variables and recursively reads Kubernetes secret files.
index.jsView on unpkg · L104The manifest names index.js as the package entrypoint.
package.jsonView on unpkg · L1This report applies to @hrmony/pladddform-codegen@49.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint sends a POST request to an external exporter as it loads.
index.jsView on unpkg · L5The code queries AWS instance metadata, including IAM role credentials and instance credentials.
index.jsView on unpkg · L82Collected AWS information is POSTed to the external exporter.
index.jsView on unpkg · L94The code copies all environment variables and recursively reads Kubernetes secret files.
index.jsView on unpkg · L104The manifest names index.js as the package entrypoint.
package.jsonView on unpkg · L1