LWA-2026-7250 MAL-2026-13369 ↗ confirmed malware

kepler@1.0.999

Malicious code in kepler (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

kepler@1.0.999 declares a dependency "flag-serial-object-syntax" as a full URL pointing to hxxps://artifacts[.]yosiroute[.]com/npm/flag-serial-object-syntax instead of a standard npm semver range. The bundled npm-shrinkwrap.json confirms this dependency has install scripts enabled (hasInstallScript: true). When npm installs this package, it will fetch the dependency from the external host, which can serve arbitrary code that executes during installation. The package itself is a minimal 687-byte stub with no real functionality — it exists solely to pull code from the non-standard registry at install time.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 02:32 AM
analyzed
Jul 30, 2026, 02:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.