@hrmony/kit-4@1.0.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17265
Ecosystem
npm
Summary
The package runs credential-harvesting code both at install time and at import time. The declared preinstall hook scripts/check-setup.mjs queries the AWS EC2 instance metadata service (IMDSv2 at 169.254.169.254) to retrieve the host's IAM role credentials, enumerates the full process.env, and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), then POSTs the collected data to https://hrnmn.dd.h4x.tv/save_instance_info_hook. The package main (index.js) contains the same collector and executes it via top-level await on require/import, POSTing to https://hrnmn.dd.h4x.tv/save_instance_info_index. Both entrypoints unconditionally beacon to hrnmn.dd.h4x.tv before credential collection. The destination is a hardcoded non-first-party host on the h4x.tv TLD, unrelated to any declared publisher domain. Installing or importing this package on an EC2 host or in a Kubernetes pod yields AWS IAM role credentials and cluster service-account tokens to the operator of hrnmn.dd.h4x.tv.
Source: amazon-inspector (cb6ac778d35433101385eb57755b6079e76c7bb3dc40306218cf5b1295d5a853)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.