OpenSSF/OSV advisory MAL-2026-17276 confirms this npm version as malicious. @hrmony/pladddform-frontend@48.99.0 ships an index.js whose top-level code, executed on require/import, POSTs to the hardcoded attacker host https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-frontend and then invokes two harvesters. aws_get() queries the AWS EC2 Instance Metadata Service at 169.254.169.254 using IMDSv2 (PUT /latest/api/token) and sweeps...
This report applies to @hrmony/pladddform-frontend@49.3.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.