The main entrypoint harvests cloud credentials, environment variables, and Kubernetes secret files, then sends them to an external host. No user action beyond importing the package is required.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint defines an external exporter URL and immediately POSTs to it at module load.
index.jsView on unpkg · L5The entrypoint requests AWS instance metadata, including IAM role credentials and EC2 identity credentials.
index.jsView on unpkg · L82Collected AWS metadata is POSTed to the external exporter.
index.jsView on unpkg · L94The entrypoint copies all environment variables and recursively reads /var/run/secrets/.
index.jsView on unpkg · L104The manifest declares index.js as the package main entrypoint.
package.jsonView on unpkg · L1This report applies to @hrmony/pladddform-partner-registry@40.14.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe entrypoint defines an external exporter URL and immediately POSTs to it at module load.
index.jsView on unpkg · L5The entrypoint requests AWS instance metadata, including IAM role credentials and EC2 identity credentials.
index.jsView on unpkg · L82Collected AWS metadata is POSTed to the external exporter.
index.jsView on unpkg · L94The entrypoint copies all environment variables and recursively reads /var/run/secrets/.
index.jsView on unpkg · L104The manifest declares index.js as the package main entrypoint.
package.jsonView on unpkg · L1