The package entrypoint harvests cloud and local secrets and sends them to an external host. This occurs automatically when the module is imported.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entrypoint immediately posts to an external exporter.
index.jsView on unpkg · L5The entrypoint collects AWS IAM role credentials, instance credentials, and user data.
index.jsView on unpkg · L82Collected AWS information is posted to the external exporter.
index.jsView on unpkg · L94The entrypoint copies all environment variables and recursively reads Kubernetes secrets.
index.jsView on unpkg · L104The manifest sets index.js as the package entrypoint.
package.jsonView on unpkg · L5This report applies to @hrmony/pladddform-shared-infrastructure@40.14.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entrypoint immediately posts to an external exporter.
index.jsView on unpkg · L5The entrypoint collects AWS IAM role credentials, instance credentials, and user data.
index.jsView on unpkg · L82Collected AWS information is posted to the external exporter.
index.jsView on unpkg · L94The entrypoint copies all environment variables and recursively reads Kubernetes secrets.
index.jsView on unpkg · L104The manifest sets index.js as the package entrypoint.
package.jsonView on unpkg · L5