Importing the package collects cloud and local secrets and sends them to an external exporter. This is an active data-exfiltration path.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint defines an external exporter URL and immediately sends a POST request.
index.jsView on unpkg · L5It requests AWS instance metadata, including IAM role credentials.
index.jsView on unpkg · L82It serializes collected instance information and posts it to the exporter.
index.jsView on unpkg · L94It copies all environment variables and recursively reads Kubernetes secret files before posting them.
index.jsView on unpkg · L104The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L5This report applies to @hrmony/pladddform-infrastructure@40.14.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint defines an external exporter URL and immediately sends a POST request.
index.jsView on unpkg · L5It requests AWS instance metadata, including IAM role credentials.
index.jsView on unpkg · L82It serializes collected instance information and posts it to the exporter.
index.jsView on unpkg · L94It copies all environment variables and recursively reads Kubernetes secret files before posting them.
index.jsView on unpkg · L104The package declares index.js as its main entrypoint.
package.jsonView on unpkg · L5