OpenSSF/OSV advisory MAL-2026-17275 confirms this npm version as malicious. On top-level module load, index.js queries the AWS instance metadata service at 169.254.169.254 (IMDSv2), retrieves the instance identity document, network interface information, and IAM security-credentials for every attached role (including temporary access key IDs, secret access keys, and session tokens), then POSTs the aggregated data to the hardcoded attacker endpoint...
This report applies to @hrmony/pladddform-core@49.3.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.