MAL-2026-17264

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit-1/MAL-2026-17264.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17264
Published
2026-09-29T16:35:04Z
Modified
2026-09-29T17:00:07Z
Summary
Malicious code in @hrmony/kit-1 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (0a4084c44ab6554d66c474338de2cb482a25b31e6822d470e08b2b2ef5b1735a)

The package executes credential-harvesting code both from its postinstall script (scripts/check-setup.mjs) and from its main entry (index.js), so theft fires on npm install and again on require/import even when lifecycle scripts are skipped. Both code paths query the EC2 Instance Metadata Service at 169.254.169.254 (IMDSv2 token flow) to retrieve instance identity, IAM role names, and the role's temporary security credentials; enumerate all of process.env; and recursively read /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets). The collected data is POSTed to https://hrmnmn.dd.h4x.tv/save_instance_info_hook and https://hrmnmn.dd.h4x.tv/save_instance_info_index. An additional unconditional beacon POST ({"c53":"hello"}) to the same host provides install/import telemetry. The h4x.tv destination has no relation to any declared publisher or purpose.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020669",
            "import_time":  "2026-09-29T16:45:39.07773716Z",
            "modified_time":  "2026-09-29T16:35:04Z",
            "sha256":  "0a4084c44ab6554d66c474338de2cb482a25b31e6822d470e08b2b2ef5b1735a",
            "source":  "amazon-inspector",
            "versions":  [
                "1.99.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @hrmony/kit-1

Package

Name
@hrmony/kit-1
View open source insights on deps.dev
Purl
pkg:npm/%40hrmony/kit-1

Affected ranges

Affected versions

1.*
1.99.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "scripts/check-setup.mjs",
            "sha256":  "777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39",
            "tlsh":  "e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"
        },
        {
            "path":  "index.js",
            "sha256":  "fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9",
            "tlsh":  "e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "kit-1-1.99.0.tgz",
            "hashes":  {
                "sha1":  "9b77077fc241bd03c83ee1c6a8d7cdca90d91d1a",
                "sha512_sri":  "sha512-ur2b1knjhEwbgwzpv13U3VozEWrgo3KVXy5q8rKl5MQI98FSWdl5VaM3u/SqJYtIb8ff66X/915Z6Gqz+CIryw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit-1/MAL-2026-17264.json"