LWA-2026-12263 MAL-2026-16297 ↗ confirmed malware

keroeltop@99.99.99

Malicious code in keroeltop (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

Dependency-confusion stub published at version 99.99.99 with an empty description. Every lifecycle hook (preinstall, install, postinstall, prepare, etc.) executes index.js, which reads the machine hostname and sends it to the remote endpoint hxxps://eo8f3m3ho26a0nm[.]m[.]pipedream[.]net/keroeltop?h=<hostname> at install time. The package exfiltrates the hostname of any machine that installs it to this third-party endpoint.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 11:27 PM
analyzed
Sep 18, 2026, 11:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.