Logo
npm

@hrmony/kit@1.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17263

Ecosystem

npm

Summary

On require/import, index.js contacts the EC2 Instance Metadata Service at 169.254.169.254 using an IMDSv2 token, enumerates the instance's IAM role security-credentials (including temporary AWS access key, secret, and session token), enumerates every entry in process.env, and recursively reads /var/run/secrets/ (Kubernetes projected service-account tokens and mounted secrets). The collected data is POSTed to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_index. package.json also declares a preinstall hook (node scripts/check_setup.mjs) intended to run a sibling variant of the same payload (scripts/check-setup.mjs) that exfiltrates to https://hrnmn.dd.h4x.tv/save_instance_info_hook; a filename hyphen/underscore mismatch appears to prevent that lifecycle path from firing, but the payload is present in the tarball. The package exports no functional API — index.js contains only the exfiltration code, and package.json metadata (description 'bip bop I get your sip sop', author 'kuhuna') is a cover story. The.h4x.tv destination is unrelated to any legitimate publisher.

Source: amazon-inspector (6976b2f9327b9a181d77cd0597ef2f657575961a3d47ef8c57de1f6d4141503d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.