keroeltopkk@99.99.99
Malicious code in keroeltopkk (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package's install/preinstall/postinstall hooks all run a bundled server.js that reads the machine hostname and sends it to the remote webhook endpoint eo8f3m3ho26a0nm[.]m[.]pipedream[.]net (path /keroeltopkk?h=<hostname>) via an HTTP GET. The package is a 461-byte stub with no functionality other than this install-time host-metadata beacon.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 11:53 PM
- analyzed
- Sep 18, 2026, 11:54 PM
Related advisories
- keroeltopgg@99.99.99
- keroeltop@99.99.99
- test1ro@99.99.99
- bulk-add-sdk@1.99.99
- test8999-auth@1.0.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test899-auth@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.