OpenSSF/OSV advisory MAL-2026-17261 confirms this npm version as malicious. On module load, the package performs top-level fetches against the AWS EC2 Instance Metadata Service using IMDSv2 (requesting a token, then reading identity-credentials/ec2, iam/security-credentials/<role>, the instance identity document, and network interface data), enumerates the entire process environment, and recursively reads /var/run/secrets/ to collect Kubernetes service-account tokens and mounted secret...
This report applies to @hrmony/gutscheinverwaltung@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.