@hrmony/pladddform-partner-registry@40.14.3
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17278
Ecosystem
npm
Summary
On import, index.js executes a top-level fetch that harvests cloud and container secrets from the installer host and POSTs them to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-partner-registry. The collection code queries the AWS EC2 Instance Metadata Service at 169.254.169.254 using IMDSv2, enumerates IAM role names under /iam/security-credentials/, fetches the temporary IAM security credentials, the instance identity document, and EC2 user-data, enumerates every entry of process.env, and recursively reads all files under /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets). The collected payload is serialized as JSON and sent to the attacker-controlled host. The package name uses a typo-shape ('pladddform') under the @hrmony scope and declares a dependency on a sibling '@hrmony/kit-5', consistent with a coordinated typosquat/dependency-confusion campaign. The package provides no legitimate functionality; its sole on-import effect is credential and secret exfiltration.
Source: amazon-inspector (e09dd7e6a7777c82ec319c374c862db40d6bf7210991dac9a7a250fda4a259e7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.