Logo
npm

@hrmony/kit-1@1.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17264

Ecosystem

npm

Summary

The package executes credential-harvesting code both from its postinstall script (scripts/check-setup.mjs) and from its main entry (index.js), so theft fires on npm install and again on require/import even when lifecycle scripts are skipped. Both code paths query the EC2 Instance Metadata Service at 169.254.169.254 (IMDSv2 token flow) to retrieve instance identity, IAM role names, and the role's temporary security credentials; enumerate all of process.env; and recursively read /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets). The collected data is POSTed to https://hrmnmn.dd.h4x.tv/save_instance_info_hook and https://hrmnmn.dd.h4x.tv/save_instance_info_index. An additional unconditional beacon POST ({"c53":"hello"}) to the same host provides install/import telemetry. The h4x.tv destination has no relation to any declared publisher or purpose.

Source: amazon-inspector (0a4084c44ab6554d66c474338de2cb482a25b31e6822d470e08b2b2ef5b1735a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.