OpenSSF/OSV advisory MAL-2026-17260 confirms this npm version as malicious. On import, index.js performs an unconditional POST beacon to https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_devtool-configuration, then queries the AWS EC2 IMDSv2 endpoint (169.254.169.254) to collect the instance identity document, user-data, network/instance metadata, and IAM security-credentials (including access key, secret key, and session token) for every attached role, and POSTs the collected...
This report applies to @hrmony/devtool-configuration@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.