MAL-2026-13433Malicious code in @ks-video/kwai-player-web (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @ks-video/kwai-player-web | 9.1.2 |
{"modified":"2026-08-06T16:25:56Z","published":"2026-08-06T16:25:56Z","schema_version":"1.7.4","id":"MAL-2026-13433","summary":"Malicious code in @ks-video/kwai-player-web (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (189f106b356a246462f37d1199e1be9191a00724014f74d1ac2a39c94c5a8222)\nOn `npm install`, the package's `postinstall` hook runs `scripts/telemetry.js`, which collects installer-side reconnaissance — `os.hostname()`, `os.userInfo().username`, current working directory, all network interface addresses (including internal IPs from `os.networkInterfaces()`), Node.js version, and the full list of environment variable names via `Object.keys(process.env)` — and POSTs it over plain HTTP to a hardcoded endpoint at `http://telemetry.debugnotyja.com/api/v1/install`. The destination domain `debugnotyja.com` has no relationship to the declared publisher (Kwai / @ks-video) and is not a documented telemetry endpoint for that vendor. Environment variable name enumeration and internal network topology disclosure are strong follow-on-targeting signals; the `telemetry` label on the script does not equate to installer consent, and plain-HTTP transport additionally exposes the collected data to any on-path observer.\n","affected":[{"package":{"ecosystem":"npm","name":"@ks-video/kwai-player-web"},"versions":["9.1.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/telemetry.js","sha256":"3a1fa260f74a0fedd38ca5a7ef54a38cf4299fa05e6f4a46dd3cf9caddf5e6e1","tlsh":"c62168a151f1145427ab2190b066181262f2d0137807f8ec75e813e62fdedf880f9749"}],"package_integrity":[{"filename":"kwai-player-web-9.1.2.tgz","hashes":{"sha1":"7ce5704981ee62cd4be2e1df23bd444673766ad6","sha512_sri":"sha512-Rq5Hk2FhM4u+ezguUarr7CSZThFbVG4DMEe1oWsJSVdixN9n5v1N45ezld7YSrl4KorcsBBfs/EAcJm9rlmAww=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ks-video/kwai-player-web/v/9.1.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016695","import_time":"2026-08-06T18:09:07.429228327Z","modified_time":"2026-08-06T16:25:56Z","sha256":"189f106b356a246462f37d1199e1be9191a00724014f74d1ac2a39c94c5a8222","source":"amazon-inspector","versions":["9.1.2"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0