LWA-2026-12291 MAL-2026-16308 ↗ confirmed malware

chat-adapter-matrix@99.99.99

Malicious code in chat-adapter-matrix (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

chat-adapter-matrix@99.99.99 is a version-squat stub (version 99.99.99, empty description, no repository) whose install, preinstall, postinstall, prepare, and start scripts all execute server.js. On install, server.js makes an HTTPS request to the Pipedream webhook endpoint eo8f3m3ho26a0nm[.]m[.]pipedream[.]net at path /vercel/chat-adapter-matrix, beaconing the package name to a remote collector. No credentials, environment variables, or files are exfiltrated; the package's sole behaviour is the install-time beacon.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 12:22 AM
analyzed
Sep 21, 2026, 12:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.