Supply-chain threat intelligence
Risk score
92
Indexed incident for clawpro-diagnostics-metrics-cls (npm).
-= Per source details. Do not edit below this line.=-
The package's dist/index.js contains hardcoded HTTP POST calls targeting http://metadata.tencentyun.com along with reads of process.platform and related host identifiers. The endpoint is a cloud-metadata-style hostname being contacted over plain HTTP from package code, not a documented SDK. The package name ("diagnostics-metrics") combined with hardcoded outbound POSTs to a fixed external endpoint at module load matches the silent-beacon / data-exfiltration shape: any installer that requires this package will have host attributes transmitted to the hardcoded destination without consent or configuration.
Affected versions
Indicators
Timeline