@hrmony/benefit-essenszuschuss@3.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17253
Ecosystem
npm
Summary
On module import, top-level code in this package harvests cloud and container secrets and posts them to a hardcoded attacker-controlled endpoint. It queries the AWS Instance Metadata Service (IMDSv2 token via PUT to /latest/api/token, then /iam/security-credentials/ and identity-credentials/ec2) to retrieve IAM role credentials, serializes the full process.env, and recursively reads /var/run/secrets/ to capture Kubernetes service-account tokens and mounted secret material. The collected data is POSTed as JSON to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_benefit-essenszuschuss. The package name mimics an internal @hrmony HR/benefits utility, consistent with a dependency-confusion payload targeting that scope; it also declares an unpinned dependency @hrmony/kit-5 (^1.0.0) that will be resolved from the public registry at install time.
Source: amazon-inspector (1a91973dc3a793ffab820317714931c69f1a992ac1ebef3f80d8028976959939)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.