keroeltopkkk@99.99.99
Malicious code in keroeltopkkk (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
keroeltopkkk@99.99.99 is a dependency-confusion stub (synthetic version 99.99.99, no description) whose install, preinstall, postinstall, and prepare lifecycle hooks all execute server.js. That script reads the machine hostname via os.hostname() and sends it to the external webhook endpoint hxxps://eo8f3m3ho26a0nm[.]m[.]pipedream[.]net/keroeltopkkk?h=<hostname> at install time. The package exfiltrates the installer's hostname to a third-party pipedream[.]net endpoint on every install.
- analyzed by
- Leitwacht
- first seen
- Sep 19, 2026, 12:00 AM
- analyzed
- Sep 19, 2026, 12:01 AM
Related advisories
- keroeltopkk@99.99.99
- keroeltopgg@99.99.99
- keroeltop@99.99.99
- test1ro@99.99.99
- bulk-add-sdk@1.99.99
- test8999-auth@1.0.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.