RuntimeWire's reverse engineering of Kimi Desktop found that Windows versions 3.1.5 and 3.1.10 automatically download a standalone program called kimiim-cli tied to the group chat feature. But before installation, the client doesn't check whether the file has been tampered with, nor does it verify the program is signed by Moonshot AI, the company behind Kimi.
The program fetches its latest version from Moonshot AI's CDN. If the release account or update pipeline gets compromised, an attacker could swap the legitimate program for malicious code, and Kimi Desktop could still install it through the normal update flow — without the attacker needing Moonshot AI's code-signing key.
The kimiim-cli currently on the CDN does have a valid Moonshot AI digital signature, and there's no evidence this issue has been exploited in the wild. The problem is that Kimi Desktop doesn't force verification of that signature before installation. RuntimeWire says it disclosed the issue to Moonshot AI in advance, but hadn't received a response by press time.