Logo
npm

@hrmony/benefitverwaltung@1.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17257

Ecosystem

npm

Summary

On top-level import, the package's main module POSTs an initial identifying beacon (body {"c53":"hello"}) to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_benefitverwaltung, then performs three concrete harvest steps and exfiltrates each to the same host: (1) an IMDSv2 request flow against 169.254.169.254 that reads instance identity, enumerates IAM role names under /iam/security-credentials/, and fetches the temporary AWS access key ID, secret access key, and session token for each role; (2) a full enumeration of process.env via Object.entries(process.env) into an envs object; (3) a recursive read of /var/run/secrets/ collecting Kubernetes-mounted service-account tokens and secret files. The collected data is sent via fetch(EXPORTER_URL, {method: 'POST', body: JSON.stringify(...)}). The destination domain h4x.tv is not associated with the @hrmony scope or any legitimate benefit-administration service. The package also declares a runtime dependency on @hrmony/kit-5 ^1.0.0 within its own scope while shipping only exfiltration code as its main, consistent with a dependency-confusion lure targeting an internal @hrmony namespace.

Source: amazon-inspector (a567d870fdf9c4fecac3e9fbb009a5b23e4450ea608d416564095680dc5bc4b2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.