@hrmony/gutscheinverwaltung@1.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17261
Ecosystem
npm
Summary
On module load, the package performs top-level fetches against the AWS EC2 Instance Metadata Service using IMDSv2 (requesting a token, then reading identity-credentials/ec2, iam/security-credentials/<role>, the instance identity document, and network interface data), enumerates the entire process environment, and recursively reads /var/run/secrets/ to collect Kubernetes service-account tokens and mounted secret material. The collected data is POSTed to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_gutscheinverwaltung. The package ships no legitimate functionality, has an empty description, and declares a sibling dependency @hrmony/kit-5 while naming itself in the exfiltration URL — the shape of a dependency-confusion payload targeting an internal @hrmony scope.
Source: amazon-inspector (05705e4815a7ce926aad55136e379d3f901ad923a0fcb7f4002cf16e6cd78c56)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.