OpenSSF/OSV advisory MAL-2026-17277 confirms this npm version as malicious. On any require/import of @hrmony/pladddform-infrastructure, top-level code POSTs a beacon to the hardcoded attacker endpoint https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_pladddform-infrastructure (host encodes the package name in the path). An aws_get() routine calls the AWS Instance Metadata Service at 169.254.169.254 using an IMDSv2 token, enumerates instance/identity metadata, iterates...
This report applies to @hrmony/pladddform-infrastructure@40.99.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.