OpenSSF/OSV advisory MAL-2026-17252 confirms this npm version as malicious. The package's main module (index.js) executes exfiltration logic at top level on import. It first sends a hello beacon via HTTP POST to the hardcoded endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_belegerfassung-pladddform, then queries the AWS EC2 Instance Metadata Service at 169.254.169.254 using IMDSv2 to enumerate ami-id, instance identity, IAM role names, and their security-credentials...
This report applies to @hrmony/belegerfassung-pladddform@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.