-= Per source details. Do not edit below this line.=-
The package runs credential-harvesting code both at install time and at import time. The declared preinstall hook scripts/check-setup.mjs queries the AWS EC2 instance metadata service (IMDSv2 at 169.254.169.254) to retrieve the host's IAM role credentials, enumerates the full process.env, and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), then POSTs the collected data to https://hrnmn.dd.h4x.tv/save_instance_info_hook. The package main (index.js) contains the same collector and executes it via top-level await on require/import, POSTing to https://hrnmn.dd.h4x.tv/save_instance_info_index. Both entrypoints unconditionally beacon to hrnmn.dd.h4x.tv before credential collection. The destination is a hardcoded non-first-party host on the h4x.tv TLD, unrelated to any declared publisher domain. Installing or importing this package on an EC2 host or in a Kubernetes pod yields AWS IAM role credentials and cluster service-account tokens to the operator of hrnmn.dd.h4x.tv.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020667",
"import_time": "2026-09-29T16:45:38.926753175Z",
"modified_time": "2026-09-29T16:34:43Z",
"sha256": "cb6ac778d35433101385eb57755b6079e76c7bb3dc40306218cf5b1295d5a853",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "scripts/check-setup.mjs",
"sha256": "777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39",
"tlsh": "e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"
},
{
"path": "index.js",
"sha256": "fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9",
"tlsh": "e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd"
}
],
"package_integrity": [
{
"filename": "kit-4-1.0.0.tgz",
"hashes": {
"sha1": "ecd341c9342b1beb7b06e6e12f9dbb99681a721d",
"sha512_sri": "sha512-pGCIja3cDXs8E7Tyv5xrde1LcOCil6RBfrs9vLhLt+fMKOolhIggkkLoY9ZxMO1nlKz3ImsPBMtQ14BNCpJvOg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit-4/MAL-2026-17265.json"