LWA-2026-12266 MAL-2026-16336 ↗ confirmed malware

keroeltopkkk@99.99.99

Malicious code in keroeltopkkk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

keroeltopkkk@99.99.99 is a dependency-confusion stub (synthetic version 99.99.99, no description) whose install, preinstall, postinstall, and prepare lifecycle hooks all execute server.js. That script reads the machine hostname via os.hostname() and sends it to the external webhook endpoint hxxps://eo8f3m3ho26a0nm[.]m[.]pipedream[.]net/keroeltopkkk?h=<hostname> at install time. The package exfiltrates the installer's hostname to a third-party pipedream[.]net endpoint on every install.

analyzed by
Leitwacht
first seen
Sep 19, 2026, 12:00 AM
analyzed
Sep 19, 2026, 12:01 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.