Logo
npm

@hrmony/pladddform-application@2.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17271

Ecosystem

npm

Summary

On module load, the package's main entry point executes three exfiltration routines that POST installer-side secrets to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-application. (1) An install beacon sends a small JSON confirmation to that URL via top-level await. (2) aws_get() contacts AWS EC2 Instance Metadata Service at 169.254.169.254, obtains an IMDSv2 token, and reads iam/security-credentials/*, identity-credentials/ec2/security-credentials/ec2-instance, the instance identity document, user-data, and network/interfaces/*, then POSTs the collected object to the attacker host. (3) local_get() enumerates all process.env entries and recursively reads every file under /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets) and POSTs the combined payload to the same host. Package metadata (misspelled scoped name @hrmony/pladddform-application, empty description, generic author, self-referential @hrmony/kit-5 dependency) is consistent with a dependency-confusion payload targeting an internal package name. Any require or import of the package on a host with an AWS IMDS endpoint or Kubernetes secret mounts exfiltrates IAM role temporary credentials, environment variables, and mounted secrets to the attacker's h4x.tv domain.

Source: amazon-inspector (6470f9f3652c9b3b65d783ca46babc5ccf24e0d8d044ca654260168e8f881e17)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.