Logo
npm

@hrmony/belegerfassung-pladddform@1.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17252

Ecosystem

npm

Summary

The package's main module (index.js) executes exfiltration logic at top level on import. It first sends a hello beacon via HTTP POST to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_belegerfassung-pladddform, then queries the AWS EC2 Instance Metadata Service at 169.254.169.254 using IMDSv2 to enumerate ami-id, instance identity, IAM role names, and their security-credentials (including short-lived ec2-instance credentials and user-data), and POSTs the harvested object to the same endpoint. It also enumerates every entry of process.env and recursively reads all files under /var/run/secrets/ (the Kubernetes service-account and secret mount point), then POSTs the combined payload to the same endpoint. The package name uses a typosquat pattern (belegerfassung-pladddform with duplicated letters under the @hrmony scope resembling @harmony) and declares an unpinned dependency @hrmony/kit-5 (^1.0.0) on the same attacker-controlled scope, extending the payload delivery surface via a transitive dependency.

Source: amazon-inspector (615255a66c44204b03e60a165c1a9b21f95ecd351bf58c355462c159c74d1017)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.