pay-methods-kmf@100.100.102
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17776
Ecosystem
npm
Summary
pay-methods-kmf@100.100.102 is a trivial stub (empty index.js, manifest description 'Frontend utilities') that ships a prebuilt Linux x64 native addon at prebuilds/linux-x64/addon.node and loads it from postinstall.js via require('./prebuilds/linux-x64/addon.node'). On install the postinstall path performs two concurrent exfiltration channels: (1) a DNS beacon that resolves a subdomain of the form <hostname>.<packagename>.db4jlbku53082dmp0d7g3mffj7s7aordk.oast.me against an interactsh/OAST collector, encoding the installer hostname and package name into the DNS label; and (2) the native addon calls gethostname, getpwuid, and getenv and issues an HTTP POST to the hardcoded bare IPv4 endpoint http://64.181.165.115/dc with body shape 'h=<hostname>&u=<user>&p=<package>&r=<npm_config_registry>', leaking the installer's hostname, username, package name, and configured npm registry URL (which may reveal internal/private registry hosts). The package ships no source for the binary, the compiled addon's symbol set (socket/connect/send/fork) is unrelated to any frontend utility, and both the OAST subdomain and the bare-IP POST endpoint are attacker-controlled infrastructure. Dependency-confusion-style version (100.100.102) and the registry-URL field in the exfil payload are consistent with internal-registry reconnaissance.
Source: amazon-inspector (07a616a1db0408a0570000c6514224d22e71c3ecee0f08268b5dd9bc96761fd2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.