MAL-2026-17265

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit-4/MAL-2026-17265.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17265
Published
2026-09-29T16:34:43Z
Modified
2026-09-29T17:00:08Z
Summary
Malicious code in @hrmony/kit-4 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (cb6ac778d35433101385eb57755b6079e76c7bb3dc40306218cf5b1295d5a853)

The package runs credential-harvesting code both at install time and at import time. The declared preinstall hook scripts/check-setup.mjs queries the AWS EC2 instance metadata service (IMDSv2 at 169.254.169.254) to retrieve the host's IAM role credentials, enumerates the full process.env, and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), then POSTs the collected data to https://hrnmn.dd.h4x.tv/save_instance_info_hook. The package main (index.js) contains the same collector and executes it via top-level await on require/import, POSTing to https://hrnmn.dd.h4x.tv/save_instance_info_index. Both entrypoints unconditionally beacon to hrnmn.dd.h4x.tv before credential collection. The destination is a hardcoded non-first-party host on the h4x.tv TLD, unrelated to any declared publisher domain. Installing or importing this package on an EC2 host or in a Kubernetes pod yields AWS IAM role credentials and cluster service-account tokens to the operator of hrnmn.dd.h4x.tv.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020667",
            "import_time":  "2026-09-29T16:45:38.926753175Z",
            "modified_time":  "2026-09-29T16:34:43Z",
            "sha256":  "cb6ac778d35433101385eb57755b6079e76c7bb3dc40306218cf5b1295d5a853",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @hrmony/kit-4

Package

Name
@hrmony/kit-4
View open source insights on deps.dev
Purl
pkg:npm/%40hrmony/kit-4

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "scripts/check-setup.mjs",
            "sha256":  "777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39",
            "tlsh":  "e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"
        },
        {
            "path":  "index.js",
            "sha256":  "fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9",
            "tlsh":  "e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "kit-4-1.0.0.tgz",
            "hashes":  {
                "sha1":  "ecd341c9342b1beb7b06e6e12f9dbb99681a721d",
                "sha512_sri":  "sha512-pGCIja3cDXs8E7Tyv5xrde1LcOCil6RBfrs9vLhLt+fMKOolhIggkkLoY9ZxMO1nlKz3ImsPBMtQ14BNCpJvOg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit-4/MAL-2026-17265.json"