@hrmony/organisationsverwaltung@7.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17270
Ecosystem
npm
Summary
@hrmony/organisationsverwaltung 7.99.0 executes credential-theft code at the top level of index.js, so simply requiring or importing the package triggers exfiltration. On load it sends a hello beacon via POST to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_organisationsverwaltung, then queries the AWS EC2 Instance Metadata Service at 169.254.169.254 (IMDSv2) to retrieve IAM role security-credentials and identity documents, enumerates all entries of process.env, and recursively reads every file under /var/run/secrets/ (the mount path for Kubernetes service-account tokens and mounted secrets). The collected AWS credentials, environment variables, and Kubernetes secrets are POSTed as a JSON payload to the same hardcoded endpoint at hrnmn.dd.h4x.tv. Package metadata (empty description, no repository, version 7.99.0 published under the @hrmony scope with a self-declared @hrmony/kit-5 dependency) is consistent with a dependency-confusion package targeting an internal @hrmony/* namespace.
Source: amazon-inspector (78807365ee9728923ec2d5d103ce7f4562b21e2fc8185483b482bb5d2f79748d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.