Logo
npm

@hrmony/benefit-mobilitaet@1.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17255

Ecosystem

npm

Summary

On module load, index.js unconditionally contacts the EC2 Instance Metadata Service at 169.254.169.254, obtains an IMDSv2 token, and retrieves instance identity, user-data, and all IAM role temporary security credentials from /iam/security-credentials/. It also enumerates every entry of process.env and recursively reads files under /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets). The collected data is POSTed as JSON to the hardcoded attacker-controlled endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_benefit-mobilitaet, whose path names the package explicitly and functions as a dependency-confusion beacon. The manifest carries an empty description, placeholder author 'kuhuna', and a single dependency @hrmony/kit-5 in a scope resembling an internal 'harmony' namespace, matching the dependency-confusion attack pattern.

Source: amazon-inspector (bf87d41e53e59a65644aaf92de291a5943afa017fbdc2068ebb6741383f60688)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.