@hrmony/pladddform-codegen@49.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17273
Ecosystem
npm
Summary
On module load, index.js unconditionally beacons to the hardcoded non-first-party endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-codegen and then performs three credential-harvest flows against the installer: (1) queries the AWS instance metadata service at 169.254.169.254 (IMDSv2), enumerates IAM role names, retrieves each role's security credentials, and collects the EC2 identity document, user-data, and network-interface metadata; (2) enumerates all process.env entries; (3) recursively reads /var/run/secrets/ (Kubernetes projected service-account tokens and mounted secrets). The collected data is POSTed to the same hardcoded attacker host. The package name is a typosquat of an @hrmony scoped package with an inflated version (49.99.0) consistent with a dependency-confusion attempt, and it declares an internal-looking sibling dependency @hrmony/kit-5. The exfiltration URL path embeds the package name, indicating a campaign-style beacon per lure.
Source: amazon-inspector (58f0706d7223f8a1ff87ac80c6e1e42af148214545e55acc865cce12fee7eec4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.