@ks-openclaw/kim@99.0.0
Malicious code in @ks-openclaw/kim (npm)
Analysis
Dependency-confusion package @ks-openclaw/kim@99.0.0 executes a reverse shell on install. The preinstall hook (preinstall.js) connects to 120[.]55[.]170[.]103:8888 via TCP, pipes the connection to cmd.exe for remote shell access, collects hostname, username, platform, architecture, Node.js version, and current working directory, and writes a proof-of-concept file to C:\poc_dependency_confusion.txt.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 02:11 AM
- analyzed
- Jul 31, 2026, 02:12 AM
Related advisories
- osinthell@1.9.5
- @types-beta/sdk@0.1.3
- paperclip-adapter-helpers@1.0.8
- test-pkg-yarn@1.0.0
- openllmapi@4.0.2
- easyllmai@3.0.1
- toast-react-slider@1.0.0
- textify-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.