Logo
npm

ksp-app@100.100.100

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC

Malicious

OSV ID

MAL-2026-17770

Ecosystem

npm

Summary

ksp-app@100.100.100 is a dependency-confusion-shaped npm package whose only payload is an opaque prebuilt Linux x64 native addon loaded at install time. package.json declares scripts.postinstall="node postinstall.js", which require()s prebuilds/linux-x64/addon.node. The tarball ships no C/C++ source, no binding.gyp, and no build tooling; index.js exports an empty object, so the entire package behavior is in the native binary. On load, the ELF addon reads the environment variables HOSTNAME, npm_package_name, and npm_config_registry and POSTs them over a raw socket to the hardcoded bare-IP endpoint http://64.181.165.115/dc (HTTP/1.0, Host: 64.181.165.115, format string h=%.40s&p=%.40s&u=%.20s&r=%.80s). The version string 100.100.100, inert JS stub, generic "Frontend utilities" description, and a beacon that reports the installer's configured npm registry are the signature of a dependency-confusion exfiltration package used to confirm installs inside victim environments and disclose internal registry URLs to a third party.

Source: amazon-inspector (b14a9fbd9fc1a48dc3ac0498f9606cecb1a56bad912c7f8a818fad332ef9ad15)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.