@hrmony/pladddform-testing@40.14.3
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17280
Ecosystem
npm
Summary
On module import, index.js executes an unconditional exfiltration payload against the installer/runtime host. It queries the AWS EC2 Instance Metadata Service at http://169.254.169.254 using IMDSv2 to enumerate the instance identity document, user-data, IAM role names, and the per-role temporary security credentials. It also enumerates every entry of process.env and recursively reads all files under /var/run/secrets/ (the standard Kubernetes service-account and secret mount). The combined data is POSTed to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-testing, and a separate top-level fetch to the same host beacons successful execution. The package ships no legitimate functionality: its only substantive file is the exfil script, the description is empty, and the name (@hrmony/pladddform-testing) plus the exfil URL path segment (pkge_hrmony_pladddform-testing) match a typosquat/dependency-confusion shape targeting an internal or similarly named scope.
Source: amazon-inspector (607004ff93f1fcd5fbf7b1cf6b5e104b7f26eb699aee3dd4f8bbb33494f0b096)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.