@hrmony/pladddform-frontend@49.3.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17276
Ecosystem
npm
Summary
@hrmony/pladddform-frontend@48.99.0 ships an index.js whose top-level code, executed on require/import, POSTs to the hardcoded attacker host https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-frontend and then invokes two harvesters. aws_get() queries the AWS EC2 Instance Metadata Service at 169.254.169.254 using IMDSv2 (PUT /latest/api/token) and sweeps /latest/meta-data/iam/security-credentials/ to collect instance identity, IAM role names, and temporary IAM security credentials. local_get() enumerates every entry of process.env and recursively reads /var/run/secrets/, capturing Kubernetes-mounted service-account tokens and secret files. Both payloads are POSTed to the same hardcoded hrnmn.dd.h4x.tv endpoint. The package has an empty description, no functional code beyond the stealer, an intentionally misspelled scope and name mimicking an internal 'harmony/platform-frontend', and declares a dependency on the similarly look-alike '@hrmony/kit-5', consistent with a dependency-confusion typosquat targeting an internal package name.
Source: amazon-inspector (8f03abfe6149423144b6d3143a66cbca7925bb6eb736b1ece350d5a344684eb9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.