OpenSSF/OSV advisory MAL-2026-17264 confirms this npm version as malicious. The package executes credential-harvesting code both from its postinstall script (scripts/check-setup.mjs) and from its main entry (index.js), so theft fires on npm install and again on require/import even when lifecycle scripts are skipped. Both code paths query the EC2 Instance Metadata Service at 169.254.169.254 (IMDSv2 token flow) to retrieve instance identity, IAM role names, and the role's temporary security...
This report applies to @hrmony/kit-1@1.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.