{"id":"MAL-2026-17744","summary":"Malicious code in kmf-vendor-pack (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129)\npackage.json defines a postinstall script that invokes `node -e` to issue an HTTPS GET to the attacker-controlled out-of-band callback host db4fe7a2e2lvaraia8k0n4amgw4ir83az.oast.pro, embedding the installer's OS hostname (os.hostname()) and username (os.userInfo().username) in query parameters. The request fires automatically on `npm install` with no caller interaction, confirming code execution on the installer's machine and leaking host-identifying data to a third-party interaction server.\n\n## Source: ossf-package-analysis (90252f22765869df637f77df2754cd36724812550151c9c7c53926bc83daad2e)\nThe OpenSSF Package Analysis project identified 'kmf-vendor-pack' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-10-09T17:30:03.288515220Z","published":"2026-10-09T15:55:48Z","database_specific":{"malicious-packages-origins":[{"sha256":"90252f22765869df637f77df2754cd36724812550151c9c7c53926bc83daad2e","source":"ossf-package-analysis","versions":["99.0.0"],"import_time":"2026-10-09T16:20:00.871582705Z","modified_time":"2026-10-09T15:55:48Z"},{"modified_time":"2026-10-09T16:53:57Z","sha256":"95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129","source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-021336","import_time":"2026-10-09T17:16:16.600140031Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/kmf-vendor-pack/v/99.0.0"}],"affected":[{"package":{"name":"kmf-vendor-pack","ecosystem":"npm","purl":"pkg:npm/kmf-vendor-pack"},"versions":["99.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"kmf-vendor-pack-99.0.0.tgz","hashes":{"sha512_sri":"sha512-zrmEJCRcINDZPd2ARMcbrgStgT9MzZdc5rS6cJjaPHulo0ghMQYdMOpo6akgrc6gl2jgpMtozatE3D58YI8M7w==","sha1":"e2e8a1b510ff4d08c1a4c2eb9323d6352c5725f9"}}],"evidence_files":[{"sha256":"c00f5e4b31d7ff303956007a49d6758283a750fa6cb3a0a49eaa7cd330c0078a","tlsh":"50e068f85535dab73dc412d88686a50bf1a2cd1a0004bc049be7238d4ad91f35bbe9a9","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/kmf-vendor-pack/MAL-2026-17744.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}