MAL-2026-17263

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit/MAL-2026-17263.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17263
Published
2026-09-29T16:34:55Z
Modified
2026-09-29T17:00:07Z
Summary
Malicious code in @hrmony/kit (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6976b2f9327b9a181d77cd0597ef2f657575961a3d47ef8c57de1f6d4141503d)

On require/import, index.js contacts the EC2 Instance Metadata Service at 169.254.169.254 using an IMDSv2 token, enumerates the instance's IAM role security-credentials (including temporary AWS access key, secret, and session token), enumerates every entry in process.env, and recursively reads /var/run/secrets/ (Kubernetes projected service-account tokens and mounted secrets). The collected data is POSTed to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_index. package.json also declares a preinstall hook (node scripts/check_setup.mjs) intended to run a sibling variant of the same payload (scripts/check-setup.mjs) that exfiltrates to https://hrnmn.dd.h4x.tv/save_instance_info_hook; a filename hyphen/underscore mismatch appears to prevent that lifecycle path from firing, but the payload is present in the tarball. The package exports no functional API — index.js contains only the exfiltration code, and package.json metadata (description 'bip bop I get your sip sop', author 'kuhuna') is a cover story. The.h4x.tv destination is unrelated to any legitimate publisher.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020668",
            "import_time":  "2026-09-29T16:45:39.008535509Z",
            "modified_time":  "2026-09-29T16:34:55Z",
            "sha256":  "6976b2f9327b9a181d77cd0597ef2f657575961a3d47ef8c57de1f6d4141503d",
            "source":  "amazon-inspector",
            "versions":  [
                "1.99.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @hrmony/kit

Package

Name
@hrmony/kit
View open source insights on deps.dev
Purl
pkg:npm/%40hrmony/kit

Affected ranges

Affected versions

1.*
1.99.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9",
            "tlsh":  "e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd"
        },
        {
            "path":  "scripts/check-setup.mjs",
            "sha256":  "777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39",
            "tlsh":  "e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"
        },
        {
            "path":  "package.json",
            "sha256":  "ef54934aa4d22a65f79a045c9866b00c360b0c0bacadb561a7a093745ae27c03",
            "tlsh":  "83d0c2204d12603369e002620c7e959b53608e6f2908bc0427eb503d809eaba48fb35d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "kit-1.99.0.tgz",
            "hashes":  {
                "sha1":  "dca6650b1ace3b90b2c2b49875479cfba994e0a7",
                "sha512_sri":  "sha512-M+xHdNOZupbxPrVi45K7X6WBteGiYPvidrTiu7axp1y9KMOZimPly9OdCnoxdQZU2HKLADYRcfPZR/f5eE78mg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit/MAL-2026-17263.json"