keroeltop@99.99.99
Malicious code in keroeltop (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
Dependency-confusion stub published at version 99.99.99 with an empty description. Every lifecycle hook (preinstall, install, postinstall, prepare, etc.) executes index.js, which reads the machine hostname and sends it to the remote endpoint hxxps://eo8f3m3ho26a0nm[.]m[.]pipedream[.]net/keroeltop?h=<hostname> at install time. The package exfiltrates the hostname of any machine that installs it to this third-party endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 11:27 PM
- analyzed
- Sep 18, 2026, 11:28 PM
Related advisories
- test1ro@99.99.99
- bulk-add-sdk@1.99.99
- test8999-auth@1.0.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test899-auth@1.0.1
- test89-auth@1.0.1
- test890-auth@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.