@hrmony/benefit-sachbezug@1.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17256
Ecosystem
npm
Summary
The package's main entry (index.js) executes at require/import time and POSTs harvested data to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_benefit-sachbezug. One path queries the AWS EC2 Instance Metadata Service (IMDSv2), obtains a token via PUT to /latest/api/token, and retrieves the instance identity document, IAM role temporary credentials via iam/security-credentials/, network and security-group metadata, and user-data. A second path enumerates all process.env entries and recursively reads /var/run/secrets/, the standard mount path for Kubernetes service-account tokens and mounted secrets, and sends both to the same author-controlled host. The package name (@hrmony/benefit-sachbezug), empty description, ISC license, and beacon body {"c53":"hello"} with the endpoint path keyed to the scope name match the dependency-confusion beacon pattern targeting an internal @hrmony scope.
Source: amazon-inspector (de40a55476bbcc5eda275f9f385396699f1b066bf1ddedb80fad053c4057c63a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.