Supply-chain threat intelligence

Incident detail

criticalnpm·credential theft·osv

Malicious code in clawpro-diagnostics-metrics-cls (npm)

clawpro-diagnostics-metrics-cls

Risk score

92

AI summary

Indexed incident for clawpro-diagnostics-metrics-cls (npm).

Description

The package's dist/index.js contains hardcoded HTTP POST calls targeting http://metadata.tencentyun.com along with reads of process.platform and related host identifiers. The endpoint is a cloud-metadata-style hostname being contacted over plain HTTP from package code, not a documented SDK. The package name ("diagnostics-metrics") combined with hardcoded outbound POSTs to a fixed external endpoint at module load matches the silent-beacon / data-exfiltration shape: any installer that requires this package will have host attributes transmitted to the hardcoded destination without consent or configuration.

Technical details

Indicators

  • affected version<function fixed() { [native code] }75%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents