kmf-vendor-pack@99.0.0
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC
OSV ID
MAL-2026-17744
Ecosystem
npm
Summary
package.json defines a postinstall script that invokes node -e to issue an HTTPS GET to the attacker-controlled out-of-band callback host db4fe7a2e2lvaraia8k0n4amgw4ir83az.oast.pro, embedding the installer's OS hostname (os.hostname()) and username (os.userInfo().username) in query parameters. The request fires automatically on npm install with no caller interaction, confirming code execution on the installer's machine and leaking host-identifying data to a third-party interaction server.
Source: amazon-inspector (95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.