chat-adapter-matrix@99.99.99
Malicious code in chat-adapter-matrix (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
chat-adapter-matrix@99.99.99 is a version-squat stub (version 99.99.99, empty description, no repository) whose install, preinstall, postinstall, prepare, and start scripts all execute server.js. On install, server.js makes an HTTPS request to the Pipedream webhook endpoint eo8f3m3ho26a0nm[.]m[.]pipedream[.]net at path /vercel/chat-adapter-matrix, beaconing the package name to a remote collector. No credentials, environment variables, or files are exfiltrated; the package's sole behaviour is the install-time beacon.
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 12:22 AM
- analyzed
- Sep 21, 2026, 12:23 AM
Related advisories
- @baanx/abis@9.9.9
- @baanx/blockchain-config@9.9.9
- @baanx/domain@9.9.9
- @baanx/common@9.9.9
- @dbbhk/ui-components@99.0.0
- ndmcmsujey@1.0.0
- starbucks-sdk@1.0.0
- chai-as-viem@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.