OpenSSF/OSV advisory MAL-2026-17265 confirms this npm version as malicious. The package runs credential-harvesting code both at install time and at import time. The declared preinstall hook scripts/check-setup.mjs queries the AWS EC2 instance metadata service (IMDSv2 at 169.254.169.254) to retrieve the host's IAM role credentials, enumerates the full process.env, and recursively reads /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets), then POSTs the collected data to...
This report applies to @hrmony/kit-4@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.