Logo
npm

@hrmony/component-library@28.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17259

Ecosystem

npm

Summary

index.js (declared as the package main) runs top-level async code on require/import that performs three exfiltration actions against a hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/. First, it POSTs a fixed beacon identifying the package to /save_instance_info_from_pkge_hrmony_component-library. Second, it queries the AWS EC2 Instance Metadata Service at 169.254.169.254 using IMDSv2, enumerates IAM roles, and reads iam/security-credentials/{role} to collect temporary AWS access keys along with the identity document and user-data, then POSTs the collected object to the same host. Third, it iterates every entry of process.env and recursively reads all files under /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets) and POSTs them to the same host. The package ships no component-library code; the exfiltration payload is its only behavior. The scope name @hrmony (missing the 'a' from @harmony) and the abnormally high 28.99.0 version are consistent with typosquat and dependency-confusion targeting.

Source: amazon-inspector (a93efe09ed89a9899669e54f614f80d91a80c59d77e0c2a2f673f92590488804)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.