bip bop I get your sip sop
OpenSSF/OSV advisory MAL-2026-17266 confirms this npm version as malicious. The package's preinstall script and its main entry (index.js) both perform identical credential-harvesting: they query the EC2 Instance Metadata Service (IMDSv2) at 169.254.169.254 for the identity document and IAM role security credentials, enumerate the entire process.env, and recursively read /var/run/secrets/ (Kubernetes service-account tokens and mounted secrets)...
This report applies to @hrmony/kit-5@1.0.1.
1.0.0, 1.0.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.