Logo
npm

kmf-vendor-pack@99.0.0

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 7:51 PM UTC

Malicious

OSV ID

MAL-2026-17744

Ecosystem

npm

Summary

package.json defines a postinstall script that invokes node -e to issue an HTTPS GET to the attacker-controlled out-of-band callback host db4fe7a2e2lvaraia8k0n4amgw4ir83az.oast.pro, embedding the installer's OS hostname (os.hostname()) and username (os.userInfo().username) in query parameters. The request fires automatically on npm install with no caller interaction, confirming code execution on the installer's machine and leaking host-identifying data to a third-party interaction server.

Source: amazon-inspector (95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.