@hrmony/middlewares@3.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17269
Ecosystem
npm
Summary
On module load, the package queries the AWS instance metadata service at 169.254.169.254 (IMDSv2) to enumerate instance identity, region, and network interfaces, then iterates IAM role security-credentials to retrieve temporary AWS access keys. It additionally serializes all entries of process.env and recursively reads Kubernetes service-account secret files under /var/run/secrets/. The aggregated payload is POSTed to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_middlewares. The package name '@hrmony/middlewares' is a lookalike of '@harmony/middlewares' (dropped 'a'), and the exfiltration host 'hrnmn.dd.h4x.tv' mirrors the same abbreviation pattern. No legitimate functionality is provided; the module's sole install/import-time effect is credential and secret exfiltration.
Source: amazon-inspector (2129e9ecca729ffb0ac23ee07dd5be18f2a853560899599981bc92b19dda4363)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.