@hrmony/lohndateien@3.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17267
Ecosystem
npm
Summary
index.js executes on module load and performs three attacker-beneficial actions against a hardcoded remote endpoint at https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_lohndateien. First, an unconditional POST beacon ({"c53":"hello"}) signals a successful install/import. Second, the module queries the AWS instance metadata service at 169.254.169.254 using IMDSv2 (PUT /latest/api/token) to enumerate instance identity, user-data, and IAM role security credentials from /latest/meta-data/iam/security-credentials/, then POSTs the collected object to the same host. Third, local_get() iterates process.env into a dictionary and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secret files), POSTing both structures to the same endpoint. The destination host is unrelated to any declared publisher infrastructure and the URL path embeds the package name, consistent with a targeted dependency-confusion or supply-chain attack. Installing and loading this package on an EC2 host or in a Kubernetes workload yields the attacker full AWS role credentials, all environment variables (including secrets and tokens), and any mounted Kubernetes secrets.
Source: amazon-inspector (743e2b2a4a3cf2758e6eb457dbc47857751d31379b13a48a2da25fc23f8e9701)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.