@hrmony/devtool-configuration@1.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17260
Ecosystem
npm
Summary
On import, index.js performs an unconditional POST beacon to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_devtool-configuration, then queries the AWS EC2 IMDSv2 endpoint (169.254.169.254) to collect the instance identity document, user-data, network/instance metadata, and IAM security-credentials (including access key, secret key, and session token) for every attached role, and POSTs the collected JSON to the same attacker host. It additionally enumerates process.env in full and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), sending both to the same endpoint. The destination host is unrelated to any AWS, Kubernetes, or npm publisher domain, and collection fires at module load with no caller opt-in.
Source: amazon-inspector (f83cb569df9c47639ee0fd16c34a4ac1b97b89733b1b468389d8032087ab233b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.