MAL-2026-11528
Dashboard / Malicious Package / MAL-2026-11528
MAL-2026-11528
Summary: Malicious code in @ks-openclaw/kim (npm)
Details: Source: amazon-inspector (a563317f01b921a7425ae16f740c8fa729db03087afacfea903db3dd90e15803) The package's preinstall lifecycle script (preinstall.js) opens a TCP socket to the hardcoded remote host 120.55.170.103:8888, spawns cmd.exe, and pipes the shell's stdio through the socket, giving the remote party full interactive command execution on the installer's machine during `npm install`. The same script also collects installer host identifiers (os.hostname(), os.userInfo().username, os.platform(), process.version, process.cwd()) while the reverse shell is connected. Cover-story strings in the file ("Proof of Concept", "Dependency Confusion") do not change the observed behavior: install-time remote code execution against the installer.
References: https://www.npmjs.com/package/@ks-openclaw/kim/v/99.0.0, https://www.npmjs.com/package/@ks-openclaw/kim/v/99.0.1
Affected packages
Package
Name: @ks-openclaw/kim
Purl: pkg:npm/%40ks-openclaw/kim
Affected ranges
Type: N/A
Events:
