StepSecurity Logo
StepSecurity
    • Get Started

    • Overview

    • Threat Center

      • Workflow Runs

      • Baseline

      • Detections

      • Suppression Rules

      • Policy Store

      • Self Hosted Runners

      • Installation

    • Action Secrets

    • Apps & PATs

  1. compromised-packages
  2. Analyze VeloraDEX SDK Compromised Package

Jobs

  • download-package
  • install-compromised-package

install-compromised-package

Harden-runner policy:
audit
Start time:07 Apr 2026 22:38:36 GMTRunner name:-Duration:48sJob labels:ubuntu-latest
Show:
Show all steps
StepPIDProcessDestinationPortStatus
Install compromised package
2362envnpm Registryregistry.npmjs.orgAPI Calls11443AllowedNot in baseline - learning07 Apr 2026 22:38:45
Import package to trigger runtime payload
2391curl89.36.224.580AllowedNot in baseline - learning07 Apr 2026 22:38:50