{"id":"MAL-2026-17263","summary":"Malicious code in @hrmony/kit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6976b2f9327b9a181d77cd0597ef2f657575961a3d47ef8c57de1f6d4141503d)\nOn require/import, index.js contacts the EC2 Instance Metadata Service at 169.254.169.254 using an IMDSv2 token, enumerates the instance's IAM role security-credentials (including temporary AWS access key, secret, and session token), enumerates every entry in process.env, and recursively reads /var/run/secrets/ (Kubernetes projected service-account tokens and mounted secrets). The collected data is POSTed to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_index. package.json also declares a preinstall hook (node scripts/check_setup.mjs) intended to run a sibling variant of the same payload (scripts/check-setup.mjs) that exfiltrates to https://hrnmn.dd.h4x.tv/save_instance_info_hook; a filename hyphen/underscore mismatch appears to prevent that lifecycle path from firing, but the payload is present in the tarball. The package exports no functional API — index.js contains only the exfiltration code, and package.json metadata (description 'bip bop I get your sip sop', author 'kuhuna') is a cover story. The.h4x.tv destination is unrelated to any legitimate publisher.\n","modified":"2026-09-29T17:00:07.249567284Z","published":"2026-09-29T16:34:55Z","database_specific":{"malicious-packages-origins":[{"versions":["1.99.0"],"id":"IN-MAL-2026-020668","import_time":"2026-09-29T16:45:39.008535509Z","modified_time":"2026-09-29T16:34:55Z","sha256":"6976b2f9327b9a181d77cd0597ef2f657575961a3d47ef8c57de1f6d4141503d","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@hrmony/kit/v/1.99.0"}],"affected":[{"package":{"name":"@hrmony/kit","ecosystem":"npm","purl":"pkg:npm/%40hrmony/kit"},"versions":["1.99.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit/MAL-2026-17263.json","indicators":{"package_integrity":[{"hashes":{"sha1":"dca6650b1ace3b90b2c2b49875479cfba994e0a7","sha512_sri":"sha512-M+xHdNOZupbxPrVi45K7X6WBteGiYPvidrTiu7axp1y9KMOZimPly9OdCnoxdQZU2HKLADYRcfPZR/f5eE78mg=="},"filename":"kit-1.99.0.tgz"}],"evidence_files":[{"sha256":"fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9","tlsh":"e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd","path":"index.js"},{"path":"scripts/check-setup.mjs","sha256":"777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39","tlsh":"e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd"},{"tlsh":"83d0c2204d12603369e002620c7e959b53608e6f2908bc0427eb503d809eaba48fb35d","path":"package.json","sha256":"ef54934aa4d22a65f79a045c9866b00c360b0c0bacadb561a7a093745ae27c03"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}