OpenSSF/OSV advisory MAL-2026-17250 confirms this npm version as malicious. index.js runs a top-level `await fetch(...)` on import that harvests installer host secrets and posts them to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_api-gateway-service-config. The code obtains an IMDSv2 token from 169.254.169.254, reads iam/security-credentials/<role> to collect short-lived AWS STS access keys, pulls instance identity, user-data, and network...
This report applies to @hrmony/api-gateway-service-config@0.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.