@hrmony/api-gateway-service-config@0.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17250
Ecosystem
npm
Summary
index.js runs a top-level await fetch(...) on import that harvests installer host secrets and posts them to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_api-gateway-service-config. The code obtains an IMDSv2 token from 169.254.169.254, reads iam/security-credentials/<role> to collect short-lived AWS STS access keys, pulls instance identity, user-data, and network info, enumerates all of process.env, and recursively reads /var/run/secrets/ to capture Kubernetes service-account tokens and mounted secrets, then POSTs the aggregated JSON to the attacker host. The package also declares a single dependency on an unpublished scoped name @hrmony/kit-5 (^1.0.0), a shape consistent with a dependency-confusion campaign against an internal @hrmony/* namespace. Merely installing and importing this package causes theft of cloud IAM credentials and cluster secrets from the host.
Source: amazon-inspector (3a48388c29a59698997efcb654da3c9182138846dad274f82ad2a1101843c5e4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.