tostpro@99.99.99
Malicious code in tostpro (npm)
Analysis
tostpro@99.99.99 is a high-version stub package (version 99.99.99) published on a name that claims to be reserved by Tellyo as a dependency-confusion / npm-squatting placeholder. The package ships no functional code and declares no install scripts; its manifest states it performs no actions. The claimed author (Tellyo Security) does not match the account that actually published the package. Because the package tarball is unavailable, no executable payload or network behaviour could be confirmed; the risk is the dependency-confusion squat shape itself — a high-version package on a name that could be resolved in place of a legitimate internal dependency.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 03:16 PM
- analyzed
- Sep 23, 2026, 03:17 PM
Related advisories
- event-hunter@1.0.0
- amoncasino@1.0.0
- casino-instant@1.0.0
- felix-spin@1.0.0
- roobet@1.0.0
- spinsy-casino@1.0.0
- casinolabcasino@1.0.0
- casino-hermes@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.