masterkrweb@9.9.9
Malicious code in masterkrweb (npm)
Analysis
TRUE POSITIVE: masterkrweb@9.9.9 is a host-fingerprinting malware beacon. Preinstall hook runs `node index.js` which exfiltrates os.hostname() and os.userInfo().username via HTTP GET to hardcoded IP 185[.]225[.]232[.]206/?h={hostname}&u={username}&pkg=masterkrweb. Package version is 9.9.9 (attacker pattern to surface above legitimate versions), description is the generic "Reserved package", publisher is a gmail address with no repository URL. Tarball scan confirmed the payload. No token-theft markers found but the hostname/username exfil to a raw IP is sufficient for classification as a credential-harvesting recon beacon. Not a benign research artifact — no research provenance or disclosure.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 01:12 AM
- analyzed
- Jun 1, 2026, 06:08 AM
Related advisories
- @corpweb-ui/wmkt-library@99.99.11
- @corpweb-ui/wmkt-library@99.99.12
- specials-resources-server@35.8.1
- @kolbo/mcp@1.57.1
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
- sme-rko-finance-front-operations-pegasus@35.8.1
- sme-rko-finance-front-operations-fee@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.