Logo
npm

@hrmony/pladddform-core@49.3.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17275

Ecosystem

npm

Summary

On top-level module load, index.js queries the AWS instance metadata service at 169.254.169.254 (IMDSv2), retrieves the instance identity document, network interface information, and IAM security-credentials for every attached role (including temporary access key IDs, secret access keys, and session tokens), then POSTs the aggregated data to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-core. In the same import-time code path, it enumerates every entry in process.env and recursively reads all files under /var/run/secrets/ (Kubernetes service account tokens and mounted secrets) and POSTs those to the same host. The package exposes no functional API; its only behavior on require/import is credential and secret harvesting. package.json also declares a runtime dependency on the sibling scoped package @hrmony/kit-5 at ^1.0.0, which is fetched from the same author scope during install. The scoped name @hrmony/pladddform-core resembles a legitimate 'platform-core' package name, and the exfil host uses an attacker-controlled domain (h4x.tv) with a self-descriptive path.

Source: amazon-inspector (e9e61c4d5d499198c568d9f255e23b407eb7e47f7272c76bf5f50a0d0db31605)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.