Logo
npm

@hrmony/pladddform-infrastructure@40.99.0

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17277

Ecosystem

npm

Summary

On any require/import of @hrmony/pladddform-infrastructure, top-level code POSTs a beacon to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-infrastructure (host encodes the package name in the path). An aws_get() routine calls the AWS Instance Metadata Service at 169.254.169.254 using an IMDSv2 token, enumerates instance/identity metadata, iterates iam/security-credentials/<role> to retrieve short-lived IAM role credentials, and ships the result to the same attacker host. A local_get() routine serializes the entire process.env and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), then POSTs the combined blob to the same endpoint. The package also declares a runtime dependency on @hrmony/kit-5 under the same scope, pulling additional code controlled by the same actor into any installer's environment. The package name and scope resemble a legitimate internal-sounding infrastructure package (typosquat/dependency-confusion shape targeting an internal '@harmony/platform-infrastructure'-style name).

Source: amazon-inspector (9a26b9f2a46bdc8abd9882683d792c8fff6d94a9b89cc68162339e7fede47ceb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.