MAL-2026-17279

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/pladddform-shared-infrastructure/MAL-2026-17279.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17279
Aliases
  • GHSA-xvjm-3hmh-7v4h
Published
2026-09-29T16:31:18Z
Modified
2026-09-29T17:30:14Z
Summary
Malicious code in @hrmony/pladddform-shared-infrastructure (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (89319d39ad6d753459be90c221d657a73f70955c63d1675b347c11b5743209cc)

On module import, index.js executes three exfiltration routines that POST harvested secrets to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-shared-infrastructure. (1) A beacon POST with body {"c53":"hello"} fires first to confirm the victim. (2) aws_get() queries the AWS Instance Metadata Service at 169.254.169.254 (IMDSv2) for instance identity, EC2 security credentials, and iterates /iam/security-credentials/ to retrieve every attached IAM role's temporary credentials, then ships the aggregated JSON to the attacker host. (3) local_get() enumerates all process.env variables and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secret volumes), POSTing both to the same host. The package name resembles an internal-looking scope (@hrmony/pladddform-shared-infrastructure with a typo in 'pladddform') consistent with a dependency-confusion lure, and declares a dependency on @hrmony/kit-5 in the same author-controlled scope that would be pulled in on install. Any host importing this package on EC2 or in Kubernetes loses its cloud IAM credentials, workload identity, and full process environment to the attacker.

Source: ghsa-malware (491f8f3411beacd1ac0faacca34f123868acfc2fb54242408efe6b186265a1fe)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020646",
            "import_time":  "2026-09-29T16:45:37.226693106Z",
            "modified_time":  "2026-09-29T16:31:18Z",
            "sha256":  "89319d39ad6d753459be90c221d657a73f70955c63d1675b347c11b5743209cc",
            "source":  "amazon-inspector",
            "versions":  [
                "40.14.3"
            ]
        },
        {
            "id":  "GHSA-xvjm-3hmh-7v4h",
            "import_time":  "2026-09-29T17:25:03.751901308Z",
            "modified_time":  "2026-09-29T17:22:10Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "SEMVER"
                }
            ],
            "sha256":  "491f8f3411beacd1ac0faacca34f123868acfc2fb54242408efe6b186265a1fe",
            "source":  "ghsa-malware"
        }
    ]
}
References
Credits

Affected packages

npm / @hrmony/pladddform-shared-infrastructure

Package

Name
@hrmony/pladddform-shared-infrastructure
View open source insights on deps.dev
Purl
pkg:npm/%40hrmony/pladddform-shared-infrastructure

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

40.*
40.14.3

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "d1887bbed78e8091a9e511d081b935f47a8fe116094bd58889b8d1e6077e036a",
            "tlsh":  "53b1768642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"
        },
        {
            "path":  "package.json",
            "sha256":  "450e743a1689ca716502cc407d73b7b7966878fd3f190a6e1bd45f5638d7110e",
            "tlsh":  "83e0d8208431997349d961a21c5dc857b7628f57940c3c0c33db541cc25eab754fd76a"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "pladddform-shared-infrastructure-40.14.3.tgz",
            "hashes":  {
                "sha1":  "140860a4a42306a31e17244f442ba8a730ed8950",
                "sha512_sri":  "sha512-WFoOvsnLg7AGBDA5pPfjVSZgskOY59wmh4eC0QB6F1tXAxfnZfGhjaD7CNt+7hZW/OtTltm5rtuzEiKd8fT6Xw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/pladddform-shared-infrastructure/MAL-2026-17279.json"