@hrmony/interfaces@0.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17262
Ecosystem
npm
Summary
index.js executes top-level async code on any require/import of the package. The code (1) obtains an AWS IMDSv2 token and fetches EC2 instance identity, IAM role temporary security credentials from /latest/meta-data/iam/security-credentials/<role> and identity-credentials/ec2/security-credentials/ec2-instance, plus user-data and network metadata; (2) serializes the full process.env; (3) recursively reads /var/run/secrets/, which on Kubernetes contains service-account tokens and mounted secrets; and (4) POSTs the aggregated JSON to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_interfaces. The package ships a single ~5KB file with an empty description under the name @hrmony/interfaces (resembling a private/internal scope), and the exfiltration URL path is tagged per-package, consistent with a dependency-confusion campaign. The exfiltrated IAM role credentials grant AWS API access under the installing host's role; captured environment variables and Kubernetes service-account tokens grant further access to CI, build, and cluster resources.
Source: amazon-inspector (b7837cf2dff543cfea2f35e0dea5f767ca7b8e8f81129f4c770e5693ed247c0e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.