metrics-pipeline-d8k2
v1.0.20
Published
Authorized security-research probe (GitHub Bug Bounty, npm in scope). Contact [email protected].
Readme
@ncurran/sandbox-recon-880538 — authorized npm-sandbox security research
This is a benign package published under the author's own @ncurran scope as part of an
authorized HackerOne / GitHub Bug Bounty engagement (npm is in scope).
On install it inspects its own execution environment (OS/host fingerprint, environment-variable key names only, network interfaces) and checks whether well-known cloud metadata endpoints are reachable from where the install script runs. It reports only status codes, response lengths, and hashes — never any credential, token value, or third-party data. It performs no persistence, no lateral movement, and no destructive action.
Purpose: to evaluate whether npm's package-analysis sandbox isolates untrusted install scripts from cloud instance-metadata services. If you are a normal consumer who installed this by accident, it has done nothing harmful — please disregard.
Contact: [email protected]
