@hrmony/mailer-pladddform@1.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17268
Ecosystem
npm
Summary
index.js executes at top-level import and performs three credential-harvesting flows directed at https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_mailer-pladddform. First, aws_get() requests an IMDSv2 token from 169.254.169.254, then walks /latest/meta-data/iam/security-credentials/ to extract IAM role credentials and the EC2 instance identity document. Second, local_get() enumerates all process.env entries and recursively reads /var/run/secrets/ via fs.readdirSync/readFileSync to collect Kubernetes ServiceAccount tokens and other mounted secrets. The collected data is POSTed as JSON to the hardcoded attacker endpoint. The package ships no mailer functionality — index.js contains only the exfiltration logic — and the name uses misspellings ('hrmony', 'pladddform') consistent with a typosquat/dependency-confusion lure. package.json also declares a same-scope dependency @hrmony/kit-5 ^1.0.0, pulling additional attacker-controlled code into the install.
Source: amazon-inspector (cc17a6ae94f3beee4d60886e3233b210660bcd01f6c5f6d2fff840e6d385973b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.