-= Per source details. Do not edit below this line.=-
index.js executes at module top level on require/import. It performs an unconditional POST check-in to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-config, then runs three collection routines and exfiltrates their output to the same host. aws_get() requests an IMDSv2 token from 169.254.169.254, enumerates the EC2 instance identity document and IAM roles, and fetches temporary AWS credentials from /iam/security-credentials/. local_get() serializes the entire process.env and recursively reads all files under /var/run/secrets/, which on Kubernetes contains mounted service-account tokens and other secrets. Each result is POSTed as JSON to the hardcoded EXPORTER_URL at hrnmn.dd.h4x.tv. The package ships no advertised functionality, has an empty description, and its scope/name (@hrmony/pladddform-config) and declared dependency (@hrmony/kit-5) use a lookalike internal-scope shape consistent with dependency-confusion targeting.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020649",
"import_time": "2026-09-29T16:45:37.503286246Z",
"modified_time": "2026-09-29T16:31:46Z",
"sha256": "2de81847796671c2a5e9f97a94fae50352b0dff0816e4f0a7dfaf707fbb92629",
"source": "amazon-inspector",
"versions": [
"40.14.3"
]
},
{
"id": "GHSA-pgw6-px39-j8m8",
"import_time": "2026-09-29T17:25:03.743491934Z",
"modified_time": "2026-09-29T17:22:04Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "4e9c92a357bb0f065c93c6370e90faebf15aa3ed8ed1c4570dab1a0fe73fc330",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "6629d9adf4946d22736221c353027aeb0a3fc07138140a58bcfee4d8c9015b4d",
"tlsh": "87b1988542fb0411159f75ab8bbba0079035d1473948addc3f9c63842f4d4ede961bcd"
},
{
"path": "package.json",
"sha256": "41332271bb05e5c9e7d23a8f68df8159e3205dd6d839d603e8bbe64c04adffe0",
"tlsh": "77e026208430997349d965a34c9dc867bbb28f6b944c3c0c33eb641c825eeb754fd7aa"
}
],
"package_integrity": [
{
"filename": "pladddform-config-40.14.3.tgz",
"hashes": {
"sha1": "8d9b6bd773ae2d9df09a37d1e54f6cf2cb9bfb00",
"sha512_sri": "sha512-PS4lrRbiJ9fRze4LRGpkkIU4IAIb3kZOf0hKYRwtu8M+I9Cb1KJ3nE56vdx2AcByBCGmB0WMUjV26sAKgYVRGA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/pladddform-config/MAL-2026-17274.json"