The main entry point actively collects cloud, environment, and Kubernetes-secret data and transmits it to an external host. No user action beyond importing the package is required.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entry point immediately posts to an external exporter.
index.jsView on unpkg · L1The AWS collection routine posts collected instance information to that exporter.
index.jsView on unpkg · L94The local collection routine copies every environment variable.
index.jsView on unpkg · L104The local routine recursively reads files beneath the Kubernetes secrets directory.
index.jsView on unpkg · L112The package declares index.js as its main entry point and no lifecycle hook.
package.jsonView on unpkg · L1This report applies to @hrmony/pladddform-testing@40.14.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entry point immediately posts to an external exporter.
index.jsView on unpkg · L1The AWS collection routine posts collected instance information to that exporter.
index.jsView on unpkg · L94The local collection routine copies every environment variable.
index.jsView on unpkg · L104The local routine recursively reads files beneath the Kubernetes secrets directory.
index.jsView on unpkg · L112The package declares index.js as its main entry point and no lifecycle hook.
package.jsonView on unpkg · L1