@hrmony/valuenet@1.99.0
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC
OSV ID
MAL-2026-17281
Ecosystem
npm
Summary
On require/import, the main module of @hrmony/valuenet auto-executes and POSTs installer-side secrets to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_valuenet. It queries the AWS Instance Metadata Service at 169.254.169.254 using IMDSv2, harvesting instance identity, EC2 identity credentials, temporary IAM role security-credentials, network-interface data, and user-data. It enumerates the entire process.env object. It recursively reads /var/run/secrets/, the mount point for Kubernetes-projected service-account tokens and secret volumes. All three payloads are transmitted to the attacker-controlled host. The package name and endpoint path (pkge_hrmony_valuenet) are consistent with a dependency-confusion probe targeting an internal @hrmony/* scope.
Source: amazon-inspector (9a6f054c1d690a418a5d18f7d88883085468cc0bdfab8c604e69a82633d2de72)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.