MAL-2026-11528

    Dashboard / Malicious Package / MAL-2026-11528

    MAL-2026-11528

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in @ks-openclaw/kim (npm)

    Details: Source: amazon-inspector (a563317f01b921a7425ae16f740c8fa729db03087afacfea903db3dd90e15803) The package's preinstall lifecycle script (preinstall.js) opens a TCP socket to the hardcoded remote host 120.55.170.103:8888, spawns cmd.exe, and pipes the shell's stdio through the socket, giving the remote party full interactive command execution on the installer's machine during `npm install`. The same script also collects installer host identifiers (os.hostname(), os.userInfo().username, os.platform(), process.version, process.cwd()) while the reverse shell is connected. Cover-story strings in the file ("Proof of Concept", "Dependency Confusion") do not change the observed behavior: install-time remote code execution against the installer.

    Affected packages

    Package

    Name: @ks-openclaw/kim

    Purl: pkg:npm/%40ks-openclaw/kim

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0
    99.0.1
    MAL-2026-11528 | CVE-DB