The package entry point actively harvests cloud metadata, environment variables, and Kubernetes secrets and sends them to an external host. No user action beyond importing the package is required.
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entry point immediately posts data to an external host.
index.jsView on unpkg · L5The entry point requests AWS instance metadata and IAM role credentials.
index.jsView on unpkg · L82The entry point collects all environment variables and Kubernetes secret files, then posts them to the external host.
index.jsView on unpkg · L104The entry point collects all environment variables and Kubernetes secret files, then posts them to the external host.
index.jsView on unpkg · L128The manifest sets index.js as the package entry point.
package.jsonView on unpkg · L1This report applies to @hrmony/valuenet@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source reaches cloud instance metadata or link-local credential endpoints.
index.jsView on unpkg · L4Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgImporting the entry point immediately posts data to an external host.
index.jsView on unpkg · L5The entry point requests AWS instance metadata and IAM role credentials.
index.jsView on unpkg · L82The entry point collects all environment variables and Kubernetes secret files, then posts them to the external host.
index.jsView on unpkg · L104The entry point collects all environment variables and Kubernetes secret files, then posts them to the external host.
index.jsView on unpkg · L128The manifest sets index.js as the package entry point.
package.jsonView on unpkg · L1