@klapp-sca/routes@99.0.1
Malicious code in @klapp-sca/routes (npm)
Analysis
@klapp-sca/routes@99.0.1 is a dependency-confusion stub whose preinstall hook (node index.js || true) runs index.js to exfiltrate host metadata. It harvests hostname, username, directory and cwd, hex-encodes the data, and leaks it via two channels: a DNS query to the callback domain oast[.]live and an HTTP POST to 172[.]201[.]213[.]59:9090. Errors are silently swallowed.
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 01:40 PM
- analyzed
- Jun 8, 2026, 01:45 PM
Related advisories
- @klapp-login-platform/routes@99.0.2
- ai-sdk-helpers@1.2.0
- ai-sdk-helpers@1.4.2
- ai-sdk-helpers@0.1.0
- ai-sdk-helpers@0.1.1
- ai-sdk-helpers@0.1.2
- ai-sdk-helpers@0.2.0
- ai-sdk-helpers@0.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.