Logo
npm

@hrmony/pladddform-shared-infrastructure@40.14.3

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17279

Ecosystem

npm

Summary

On module import, index.js executes three exfiltration routines that POST harvested secrets to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-shared-infrastructure. (1) A beacon POST with body {"c53":"hello"} fires first to confirm the victim. (2) aws_get() queries the AWS Instance Metadata Service at 169.254.169.254 (IMDSv2) for instance identity, EC2 security credentials, and iterates /iam/security-credentials/ to retrieve every attached IAM role's temporary credentials, then ships the aggregated JSON to the attacker host. (3) local_get() enumerates all process.env variables and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secret volumes), POSTing both to the same host. The package name resembles an internal-looking scope (@hrmony/pladddform-shared-infrastructure with a typo in 'pladddform') consistent with a dependency-confusion lure, and declares a dependency on @hrmony/kit-5 in the same author-controlled scope that would be pulled in on install. Any host importing this package on EC2 or in Kubernetes loses its cloud IAM credentials, workload identity, and full process environment to the attacker.

Source: amazon-inspector (89319d39ad6d753459be90c221d657a73f70955c63d1675b347c11b5743209cc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.