LWA-2026-7295 MAL-2026-11528 ↗ confirmed malware

@ks-openclaw/kim@99.0.0

Malicious code in @ks-openclaw/kim (npm)

Analysis

Dependency-confusion package @ks-openclaw/kim@99.0.0 executes a reverse shell on install. The preinstall hook (preinstall.js) connects to 120[.]55[.]170[.]103:8888 via TCP, pipes the connection to cmd.exe for remote shell access, collects hostname, username, platform, architecture, Node.js version, and current working directory, and writes a proof-of-concept file to C:\poc_dependency_confusion.txt.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 02:11 AM
analyzed
Jul 31, 2026, 02:12 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.