Importing the declared entrypoint automatically harvests cloud and local secrets and sends them to an external host. This is a confirmed data-exfiltration path.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint sends a POST request to an external host during module evaluation.
index.jsView on unpkg · L5It requests AWS instance metadata, including IAM role credentials and user data, then posts the collected object externally.
index.jsView on unpkg · L82It requests AWS instance metadata, including IAM role credentials and user data, then posts the collected object externally.
index.jsView on unpkg · L94It copies all process environment variables and recursively reads the Kubernetes secrets directory.
index.jsView on unpkg · L104The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L5This report applies to @hrmony/pladddform-config@40.14.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint sends a POST request to an external host during module evaluation.
index.jsView on unpkg · L5It requests AWS instance metadata, including IAM role credentials and user data, then posts the collected object externally.
index.jsView on unpkg · L82It requests AWS instance metadata, including IAM role credentials and user data, then posts the collected object externally.
index.jsView on unpkg · L94It copies all process environment variables and recursively reads the Kubernetes secrets directory.
index.jsView on unpkg · L104The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L5