kmf-bootstrap@100.100.106
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC
OSV ID
MAL-2026-17746
Ecosystem
npm
Summary
On npm install, the package's postinstall script performs two exfiltration actions. First, it reads the installer's hostname and npm_package_name and issues DNS resolutions for a label of the form <host>.<pkg>.db4jlbku53082dmp0d7g3mffj7s7aordk.oast.me, leaking those identifiers to an Interactsh (oast.me) collaborator over DNS. Second, postinstall.js require()s a shipped Linux x64 native addon at prebuilds/linux-x64/addon.node that calls gethostname() and getpwuid()->pw_name and reads the npm_package_name and npm_config_registry environment variables, then opens a raw socket and sends an HTTP POST with body h=<host>&u=<user>&p=<pkg>&r=<registry> to the bare IP 64.181.165.115 (Host header 64.181.165.115, path /dc, HTTP/1.0, no TLS). The destination is a bare IP with no relation to the package publisher and the npm_config_registry value can disclose a private/internal registry URL from the installer's.npmrc. The native component is opaque code auto-executed during install with host-level network egress. The package name resembles the common 'bootstrap' naming convention, consistent with a dependency-confusion / typosquat lure whose purpose is to beacon successful installs and private registry metadata.
Source: amazon-inspector (b95cb55a24f11248b1635861f0a10a3cb41bc4ee6ac7e2100439ca7c947bba74)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.