The package exfiltrates cloud credentials, environment variables, and Kubernetes secrets when its entrypoint is imported. No user action or configuration gate is present.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entrypoint immediately posts to an external exporter.
index.jsView on unpkg · L5The entrypoint requests AWS IAM role credentials, instance credentials, and user data.
index.jsView on unpkg · L83The entrypoint copies all environment variables and Kubernetes secret files, posts them to the exporter, and runs both collectors on import.
index.jsView on unpkg · L128This report applies to @hrmony/pladddform-core@2.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entrypoint immediately posts to an external exporter.
index.jsView on unpkg · L5The entrypoint requests AWS IAM role credentials, instance credentials, and user data.
index.jsView on unpkg · L83The entrypoint copies all environment variables and Kubernetes secret files, posts them to the exporter, and runs both collectors on import.
index.jsView on unpkg · L128