masterkrweb@9.9.9
Malicious code in masterkrweb (npm)
Analysis
TRUE POSITIVE: masterkrweb@9.9.9 is a host-fingerprinting malware beacon. Preinstall hook runs `node index.js` which exfiltrates os.hostname() and os.userInfo().username via HTTP GET to hardcoded IP 185[.]225[.]232[.]206/?h={hostname}&u={username}&pkg=masterkrweb. Package version is 9.9.9 (attacker pattern to surface above legitimate versions), description is the generic "Reserved package", publisher is a gmail address with no repository URL. Tarball scan confirmed the payload. No token-theft markers found but the hostname/username exfil to a raw IP is sufficient for classification as a credential-harvesting recon beacon. Not a benign research artifact — no research provenance or disclosure.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 01:12 AM
- analyzed
- Jun 1, 2026, 06:08 AM
Related advisories
- @convera/ui-shared@0.0.2
- @convera/ui-shared@0.0.3
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- swiper_angular@5.9999.0
- fundraiserserv@28.0.0
- preferenceslifecycle-paypal@28.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.