-= Per source details. Do not edit below this line.=-
On require/import, index.js contacts the EC2 Instance Metadata Service at 169.254.169.254 using an IMDSv2 token, enumerates the instance's IAM role security-credentials (including temporary AWS access key, secret, and session token), enumerates every entry in process.env, and recursively reads /var/run/secrets/ (Kubernetes projected service-account tokens and mounted secrets). The collected data is POSTed to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_index. package.json also declares a preinstall hook (node scripts/check_setup.mjs) intended to run a sibling variant of the same payload (scripts/check-setup.mjs) that exfiltrates to https://hrnmn.dd.h4x.tv/save_instance_info_hook; a filename hyphen/underscore mismatch appears to prevent that lifecycle path from firing, but the payload is present in the tarball. The package exports no functional API — index.js contains only the exfiltration code, and package.json metadata (description 'bip bop I get your sip sop', author 'kuhuna') is a cover story. The.h4x.tv destination is unrelated to any legitimate publisher.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020668",
"import_time": "2026-09-29T16:45:39.008535509Z",
"modified_time": "2026-09-29T16:34:55Z",
"sha256": "6976b2f9327b9a181d77cd0597ef2f657575961a3d47ef8c57de1f6d4141503d",
"source": "amazon-inspector",
"versions": [
"1.99.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9",
"tlsh": "e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd"
},
{
"path": "scripts/check-setup.mjs",
"sha256": "777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39",
"tlsh": "e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"
},
{
"path": "package.json",
"sha256": "ef54934aa4d22a65f79a045c9866b00c360b0c0bacadb561a7a093745ae27c03",
"tlsh": "83d0c2204d12603369e002620c7e959b53608e6f2908bc0427eb503d809eaba48fb35d"
}
],
"package_integrity": [
{
"filename": "kit-1.99.0.tgz",
"hashes": {
"sha1": "dca6650b1ace3b90b2c2b49875479cfba994e0a7",
"sha512_sri": "sha512-M+xHdNOZupbxPrVi45K7X6WBteGiYPvidrTiu7axp1y9KMOZimPly9OdCnoxdQZU2HKLADYRcfPZR/f5eE78mg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit/MAL-2026-17263.json"