id: npm-anonymous-cli info: name: NPM Anonymous CLI Metrics Exposure author: DhiyaneshDK severity: info reference: - https://github.com/maurosoria/dirsearch/blob/master/db/dicc.txt metadata: verified: true shodan-query: html:"anonymous-cli-metrics.json" tags: exposure,npm,config,files requests: - method: GET path: - '{{BaseURL}}/.npm/anonymous-cli-metrics.json' - '{{BaseURL}}/anonymous-cli-metrics.json' stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - '"metricId":' - '"metrics":' - '"successfulInstalls":' condition: and - type: word part: header words: - "application/json"