StepSecurity Logo
StepSecurity
  • Get Started

  • Overview

  • Workflow Runs

    Baseline

    Detections

    Suppression Rules

    Policy Store

    Self Hosted Runners

  • Apps & PATs

  • Action Secrets

  • Settings

  1. compromised-packages
  2. Analyze VeloraDEX SDK Compromised Package

Jobs

  • download-package
  • install-compromised-package

install-compromised-package

Harden-runner policy:
audit
Start time:07 Apr 2026 22:38:36 GMTRunner name:-Duration:48sJob labels:ubuntu-latest
Show:
Show all steps
StepPIDProcessDestinationPortStatus
Install compromised package
2362envnpm Registryregistry.npmjs.orgAPI Calls11443AllowedNot in baseline - learning07 Apr 2026 22:38:45
Import package to trigger runtime payload
2391curl89.36.224.580AllowedNot in baseline - learning07 Apr 2026 22:38:50