-= Per source details. Do not edit below this line.=-
On import, index.js performs an unconditional POST beacon to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_devtool-configuration, then queries the AWS EC2 IMDSv2 endpoint (169.254.169.254) to collect the instance identity document, user-data, network/instance metadata, and IAM security-credentials (including access key, secret key, and session token) for every attached role, and POSTs the collected JSON to the same attacker host. It additionally enumerates process.env in full and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), sending both to the same endpoint. The destination host is unrelated to any AWS, Kubernetes, or npm publisher domain, and collection fires at module load with no caller opt-in.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020637",
"import_time": "2026-09-29T16:45:36.497944276Z",
"modified_time": "2026-09-29T16:29:48Z",
"sha256": "f83cb569df9c47639ee0fd16c34a4ac1b97b89733b1b468389d8032087ab233b",
"source": "amazon-inspector",
"versions": [
"1.99.0"
]
},
{
"id": "GHSA-qh4w-rc3m-9898",
"import_time": "2026-09-29T17:25:03.745793752Z",
"modified_time": "2026-09-29T17:22:03Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "7ed4ffc5156a0dbadb808bbee9d2de33232ef0814021affaf7dcecf347025caf",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "bb78004d5b126b4b49f804ec4a89850f8742cdc07ae29d0a4eb85866dfefd8ea",
"tlsh": "f9b1988642fb0411159f75ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd"
}
],
"package_integrity": [
{
"filename": "devtool-configuration-1.99.0.tgz",
"hashes": {
"sha1": "36a46e337344593e1a6d4519fa94b4dd4506d4ac",
"sha512_sri": "sha512-aWtV6OKwpM2PzipHDQkQ5McproGKIAkZ1pCI0gw9Y6QbIn9QDSC8aI99oANFUVvJFQrLP5B4GNRCuzLg4whrrA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/devtool-configuration/MAL-2026-17260.json"