-= Per source details. Do not edit below this line.=-
package.json defines a postinstall script that invokes node -e to issue an HTTPS GET to the attacker-controlled out-of-band callback host db4fe7a2e2lvaraia8k0n4amgw4ir83az.oast.pro, embedding the installer's OS hostname (os.hostname()) and username (os.userInfo().username) in query parameters. The request fires automatically on npm install with no caller interaction, confirming code execution on the installer's machine and leaking host-identifying data to a third-party interaction server.
The OpenSSF Package Analysis project identified 'kmf-vendor-pack' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-10-09T16:20:00.871582705Z",
"modified_time": "2026-10-09T15:55:48Z",
"sha256": "90252f22765869df637f77df2754cd36724812550151c9c7c53926bc83daad2e",
"source": "ossf-package-analysis",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-021336",
"import_time": "2026-10-09T17:16:16.600140031Z",
"modified_time": "2026-10-09T16:53:57Z",
"sha256": "95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "c00f5e4b31d7ff303956007a49d6758283a750fa6cb3a0a49eaa7cd330c0078a",
"tlsh": "50e068f85535dab73dc412d88686a50bf1a2cd1a0004bc049be7238d4ad91f35bbe9a9"
}
],
"package_integrity": [
{
"filename": "kmf-vendor-pack-99.0.0.tgz",
"hashes": {
"sha1": "e2e8a1b510ff4d08c1a4c2eb9323d6352c5725f9",
"sha512_sri": "sha512-zrmEJCRcINDZPd2ARMcbrgStgT9MzZdc5rS6cJjaPHulo0ghMQYdMOpo6akgrc6gl2jgpMtozatE3D58YI8M7w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/kmf-vendor-pack/MAL-2026-17744.json"