
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@kozen/secret
Advanced tools
Module for the Kozen framework that provides support for key vault secret managers
Kozen-Secret extends the Kozen automation ecosystem with a unified way to manage API keys, credentials, and certificates across multiple secret backends. By inheriting Kozen’s dependency injection, structured logging, and multi-interface runtime, teams can expose the same secret-management capabilities through CLI actions or Model Context Protocol (MCP) tools with minimal additional wiring Kozen Wiki.
Kozen provides a lightweight task execution framework that mixes automation pipelines, IaC orchestrators, and MCP-aware assistants under one configuration-driven runtime Kozen Wiki. Kozen-Secret plugs into that foundation the same way other modules—such as Kozen Triggers for change-stream automation—register controllers and services via the Kozen IoC container Kozen Triggers Wiki. This keeps the operator experience consistent: existing Kozen deployments can load the secret module through configuration, and newcomers can bootstrap both modules side by side.
Kozen-Secret bundles delegates for AWS Secrets Manager—focused on retrieving JSON secrets through the AWS SDK—and MongoDB Client-Side Field Level Encryption (CSFLE), which stores encrypted documents with optional AWS KMS support when running in hybrid environments AWS Secrets Manager Overview MongoDB CSFLE Guide. The module bridges both providers through a shared controller, so operators choose the backend per action (--driver=aws|mdb) while the IoC configuration resolves credentials, regions, and database settings.
The provider architecture is intentionally pluggable; future releases target additional enterprise vaults such as Azure Key Vault, Google Cloud Secret Manager, HashiCorp Vault, CyberArk Conjur, and 1Password Secrets Automation. Because the module relies on standard Kozen composition rules, it can co-exist with workflow modules that trigger rotations, audit access, or hydrate application configuration at deploy time—streamlining secret operations across automations inspired by Kozen Triggers’ self-hosted patterns Kozen Triggers Wiki.
← Previous: Home | Next: Introduction →
FAQs
Module for the Kozen framework that provides support for key vault secret managers
We found that @kozen/secret demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.