@klapp-login-platform/routes@99.0.2
Malicious code in @klapp-login-platform/routes (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
@klapp-login-platform/routes@99.0.2 is an 808-byte dependency-confusion stub whose preinstall hook (node index.js || true) fires index.js, a dual-channel host-metadata beacon. It collects hostname, username, __dirname and cwd, hex-encodes them, and exfiltrates via a DNS resolution to the callback domain d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast[.]live and an HTTP POST of the same JSON to 172[.]201[.]213[.]59:9090/c. The 'security research' description has no repository URL or program reference and masks the dual-exfil stealer.
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 01:41 PM
- analyzed
- Jun 8, 2026, 01:44 PM
Related advisories
- ai-sdk-helpers@1.2.0
- ai-sdk-helpers@1.4.2
- ai-sdk-helpers@0.1.0
- ai-sdk-helpers@0.1.1
- ai-sdk-helpers@0.1.2
- ai-sdk-helpers@0.2.0
- ai-sdk-helpers@0.2.1
- ai-sdk-helpers@0.3.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.