keroeltopgg@99.99.99
Malicious code in keroeltopgg (npm)
T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's main entry point (index.js) reads the machine hostname and sends it to a remote webhook endpoint at eo8f3m3ho26a0nm[.]m[.]pipedream[.]net under the path /keroeltopgg, using the "requests" dependency. The package also declares a large set of lifecycle scripts (preinstall, install, postinstall, prepare, etc.) that only print placeholder messages. The hostname beacon exfiltrates installer host metadata to the attacker-controlled pipedream[.]net endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 11:39 PM
- analyzed
- Sep 18, 2026, 11:40 PM
Related advisories
- bulk-add-sdk@1.99.99
- test8999-auth@1.0.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test89-auth@1.0.1
- test890-auth@1.0.0
- my-ctf-helper-script-9921@1.0.0
- sorrawit-dev-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.