id: npm-anonymous-cli info: name: NPM Anonymous CLI Metrics Exposure author: DhiyaneshDK severity: info reference: - https://github.com/maurosoria/dirsearch/blob/master/db/dicc.txt metadata: verified: true max-request: 2 shodan-query: html:"anonymous-cli-metrics.json" tags: exposure,npm,config,files http: - method: GET path: - '{{BaseURL}}/.npm/anonymous-cli-metrics.json' - '{{BaseURL}}/anonymous-cli-metrics.json' stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - '"metricId":' - '"metrics":' - '"successfulInstalls":' condition: and - type: word part: header words: - "application/json" # digest: 4b0a004830460221008862d5fb8f1ed2ee35596c48dab6f36c68bc5d1c0f74746809c60b7e99dc269f0221009773f6d4ac3375e83fc3aec538dfcb492af56b9a1c7a556aa35abb244f1a51ab:922c64590222798bb761d5b6d8e72950