Logo
npm

kmf-vendor-pack@100.100.106

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17744

Ecosystem

npm

Summary

kmf-vendor-pack@100.100.100 is a dependency-confusion lure. package.json declares postinstall: node postinstall.js, which require()s a shipped prebuilt Linux x64 N-API addon at prebuilds/linux-x64/addon.node. The addon's napi_register_module_v1 Init routine calls fork(), opens a socket, connects to the hardcoded bare IP 64.181.165.115, and sends POST /dc HTTP/1.0 with body h=<HOSTNAME>&p=<npm_package_name>&u=<user>&r=<npm_config_registry>, leaking the installing host's name, the resolved package name, and the configured npm registry URL to attacker infrastructure over plain TCP. The native binary ships with no accompanying C/C++ sources, no binding.gyp, and no legitimate functionality matching the stated Frontend utilities purpose; the JS entry point is an empty module.exports = {}. The version number 100.100.100 is implausibly high and consistent with resolution-winning against an internal package of the same name. Installing this package causes immediate outbound disclosure of install-environment and internal-registry metadata to the attacker.

Source: amazon-inspector (c6e1c289f2890e0e06ab31a8d6cf5dbc8deabc26054cb44a0c60295c29a74506)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.