Logo
npm

@hrmony/pladddform-config@40.14.3

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17274

Ecosystem

npm

Summary

index.js executes at module top level on require/import. It performs an unconditional POST check-in to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-config, then runs three collection routines and exfiltrates their output to the same host. aws_get() requests an IMDSv2 token from 169.254.169.254, enumerates the EC2 instance identity document and IAM roles, and fetches temporary AWS credentials from /iam/security-credentials/<role>. local_get() serializes the entire process.env and recursively reads all files under /var/run/secrets/, which on Kubernetes contains mounted service-account tokens and other secrets. Each result is POSTed as JSON to the hardcoded EXPORTER_URL at hrnmn.dd.h4x.tv. The package ships no advertised functionality, has an empty description, and its scope/name (@hrmony/pladddform-config) and declared dependency (@hrmony/kit-5) use a lookalike internal-scope shape consistent with dependency-confusion targeting.

Source: amazon-inspector (2de81847796671c2a5e9f97a94fae50352b0dff0816e4f0a7dfaf707fbb92629)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.