{"id":"MAL-2026-17265","summary":"Malicious code in @hrmony/kit-4 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cb6ac778d35433101385eb57755b6079e76c7bb3dc40306218cf5b1295d5a853)\nThe package runs credential-harvesting code both at install time and at import time. The declared preinstall hook scripts/check-setup.mjs queries the AWS EC2 instance metadata service (IMDSv2 at 169.254.169.254) to retrieve the host's IAM role credentials, enumerates the full process.env, and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), then POSTs the collected data to https://hrnmn.dd.h4x.tv/save_instance_info_hook. The package main (index.js) contains the same collector and executes it via top-level await on require/import, POSTing to https://hrnmn.dd.h4x.tv/save_instance_info_index. Both entrypoints unconditionally beacon to hrnmn.dd.h4x.tv before credential collection. The destination is a hardcoded non-first-party host on the h4x.tv TLD, unrelated to any declared publisher domain. Installing or importing this package on an EC2 host or in a Kubernetes pod yields AWS IAM role credentials and cluster service-account tokens to the operator of hrnmn.dd.h4x.tv.\n","modified":"2026-09-29T17:00:08.148568235Z","published":"2026-09-29T16:34:43Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020667","import_time":"2026-09-29T16:45:38.926753175Z","modified_time":"2026-09-29T16:34:43Z","sha256":"cb6ac778d35433101385eb57755b6079e76c7bb3dc40306218cf5b1295d5a853","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@hrmony/kit-4/v/1.0.0"}],"affected":[{"package":{"name":"@hrmony/kit-4","ecosystem":"npm","purl":"pkg:npm/%40hrmony/kit-4"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"777f182f3318734f8702f9d063920da379e415932d54045bf168d1477d079f39","tlsh":"e0b1878642fb0411159f75ab8bbba1079036d1473948addc3f9c63842f4e4edea61bcd","path":"scripts/check-setup.mjs"},{"tlsh":"e0b1968642fb0411159f79ab8bbba0079036d1473948addc3f9c63842f4e4edea61bcd","path":"index.js","sha256":"fabbdce7eb1681bd0ffe1e9d1586eea9819aa2c391cf4950e83811805815b0c9"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-pGCIja3cDXs8E7Tyv5xrde1LcOCil6RBfrs9vLhLt+fMKOolhIggkkLoY9ZxMO1nlKz3ImsPBMtQ14BNCpJvOg==","sha1":"ecd341c9342b1beb7b06e6e12f9dbb99681a721d"},"filename":"kit-4-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hrmony/kit-4/MAL-2026-17265.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}