OpenSSF/OSV advisory MAL-2026-17267 confirms this npm version as malicious. index.js executes on module load and performs three attacker-beneficial actions against a hardcoded remote endpoint at https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_lohndateien. First, an unconditional POST beacon ({"c53":"hello"}) signals a successful install/import. Second, the module queries the AWS instance metadata service at 169.254.169.254 using IMDSv2 (PUT /latest/api/token) to enumerate...
This report applies to @hrmony/lohndateien@3.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.