Logo
npm

@hrmony/pladddform-cli@40.14.3

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17272

Ecosystem

npm

Summary

On require/import, index.js performs three attacker-benefiting actions against a hardcoded endpoint at https://hrnmn.dd.h4x.tv/. First, it POSTs an unconditional install/import beacon ({'c53':'hello'}) to that host. Second, aws_get() contacts the EC2 Instance Metadata Service at 169.254.169.254, obtains an IMDSv2 token, enumerates IAM roles under /iam/security-credentials/, and retrieves each role's temporary AWS credentials along with user-data and the instance identity document, then POSTs them to the same host. Third, local_get() enumerates every entry in process.env and recursively reads files under /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets) and POSTs the aggregated dump to the same host. The destination domain is unrelated to any AWS, Kubernetes, or legitimate telemetry provider, and the exfiltrated material (IAM instance-role STS credentials, environment variables, and Kubernetes secret material) enables immediate cloud-account and cluster takeover. The package name '@hrmony/pladddform-cli' also resembles a legitimate 'harmony/platform-cli' identifier with letter alterations consistent with typosquatting.

Source: amazon-inspector (81b9c27ba35a6978a0731d77b7d5fec367f4c2a8b4acc5838588071c89886fa4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.