Logo
npm

@hrmony/account-management@1.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17249

Ecosystem

npm

Summary

The main module executes on require/import via a top-level await. It queries the AWS IMDSv2 metadata service at 169.254.169.254 to retrieve instance identity, IAM role temporary credentials, user-data, and network information; enumerates all of process.env; and recursively reads Kubernetes-mounted secrets from /var/run/secrets/. The collected data is POSTed to the hardcoded attacker-controlled endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_account-management. The package name uses a private-looking scope (@hrmony) and declares an unpinned dependency on @hrmony/kit-5, consistent with a dependency-confusion / scope-squat attack targeting an internal npm scope.

Source: amazon-inspector (67b699bc4a206505ba0cf224888996e37fe00dff5ffb737e3b95b9fd139b910f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.