MAL-2026-17744

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/kmf-vendor-pack/MAL-2026-17744.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17744
Published
2026-10-09T15:55:48Z
Modified
2026-10-09T17:30:03Z
Summary
Malicious code in kmf-vendor-pack (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129)

package.json defines a postinstall script that invokes node -e to issue an HTTPS GET to the attacker-controlled out-of-band callback host db4fe7a2e2lvaraia8k0n4amgw4ir83az.oast.pro, embedding the installer's OS hostname (os.hostname()) and username (os.userInfo().username) in query parameters. The request fires automatically on npm install with no caller interaction, confirming code execution on the installer's machine and leaking host-identifying data to a third-party interaction server.

Source: ossf-package-analysis (90252f22765869df637f77df2754cd36724812550151c9c7c53926bc83daad2e)

The OpenSSF Package Analysis project identified 'kmf-vendor-pack' @ 99.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-10-09T16:20:00.871582705Z",
            "modified_time": "2026-10-09T15:55:48Z",
            "sha256": "90252f22765869df637f77df2754cd36724812550151c9c7c53926bc83daad2e",
            "source": "ossf-package-analysis",
            "versions": [
                "99.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021336",
            "import_time": "2026-10-09T17:16:16.600140031Z",
            "modified_time": "2026-10-09T16:53:57Z",
            "sha256": "95ddc660098b1c73a1899ad3fe471b53ce562ca033669fa64622ff386d774129",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / kmf-vendor-pack

Package

Name
kmf-vendor-pack
View open source insights on deps.dev
Purl
pkg:npm/kmf-vendor-pack

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "c00f5e4b31d7ff303956007a49d6758283a750fa6cb3a0a49eaa7cd330c0078a",
            "tlsh": "50e068f85535dab73dc412d88686a50bf1a2cd1a0004bc049be7238d4ad91f35bbe9a9"
        }
    ],
    "package_integrity": [
        {
            "filename": "kmf-vendor-pack-99.0.0.tgz",
            "hashes": {
                "sha1": "e2e8a1b510ff4d08c1a4c2eb9323d6352c5725f9",
                "sha512_sri": "sha512-zrmEJCRcINDZPd2ARMcbrgStgT9MzZdc5rS6cJjaPHulo0ghMQYdMOpo6akgrc6gl2jgpMtozatE3D58YI8M7w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/kmf-vendor-pack/MAL-2026-17744.json"