@hrmony/cdk-constructs@5.3.5
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17258
Ecosystem
npm
Summary
On require/import, index.js executes top-level async code that harvests AWS EC2 instance metadata via IMDSv2 (including IAM role security credentials fetched from http://169.254.169.254/latest/meta-data/iam/security-credentials/), serializes the entire process.env, and recursively reads files under /var/run/secrets/ (Kubernetes service account tokens and mounted secrets). The collected data is POSTed as JSON to a hardcoded external endpoint at https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_cdk-constructs. The package name uses the scope @hrmony, a one-character deletion of the @harmony scope, consistent with typosquat targeting of developers looking for AWS CDK constructs. package.json also declares a runtime dependency on @hrmony/kit-5 at ^1.0.0, an unpinned scoped package under the same attacker-controlled scope, resolved and installed alongside this package.
Source: amazon-inspector (6601c44353f60d117ef4e1ea09f9d2c997cde4375af70c49c628b38db8f1b55a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.