ksp-client-registry@100.100.101
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17771
Ecosystem
npm
Summary
The npm package ksp-client-registry@100.100.100 ships a prebuilt native addon at prebuilds/linux-x64/addon.node that is loaded by the package main (index.js require of./prebuilds/linux-x64/addon). On load the addon reads the HOSTNAME, npm_package_name, and npm_config_registry environment variables and opens a raw TCP socket to the hardcoded IP 64.181.165.115, sending them in an HTTP request of the form 'POST /dc HTTP/1.0' with a body shaped as 'h=<hostname>&p=<package>&u=<user>&r=<registry>'. ELF strings corroborate the behavior: '64.181.165.115', 'POST /dc HTTP/1.0', 'Host: 64.181.165.115', 'HOSTNAME', 'npm_package_name', 'npm_config_registry', and imports of socket/connect/send/fork/getenv/inet_pton. package.json declares a postinstall ('node postinstall.js') providing an install-time footprint, and any require() of the package triggers the beacon regardless. The addon exposes no legitimate N-API functionality beyond module registration. The implausibly high version (100.100.100) and generic registry-style name are consistent with a dependency-confusion probe designed to be resolved in place of an internal package and to report back the victim host, internal package name, and configured registry URL to the operator.
Source: amazon-inspector (3b11a639f5149e4b1c17e64eb78f226abece5ed03152b5933333a3cb56284018)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.