kepler@1.0.999
Malicious code in kepler (npm)
Analysis
kepler@1.0.999 declares a dependency "flag-serial-object-syntax" as a full URL pointing to hxxps://artifacts[.]yosiroute[.]com/npm/flag-serial-object-syntax instead of a standard npm semver range. The bundled npm-shrinkwrap.json confirms this dependency has install scripts enabled (hasInstallScript: true). When npm installs this package, it will fetch the dependency from the external host, which can serve arbitrary code that executes during installation. The package itself is a minimal 687-byte stub with no real functionality — it exists solely to pull code from the non-standard registry at install time.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 02:32 AM
- analyzed
- Jul 30, 2026, 02:33 AM
Related advisories
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
- utils-style-engine@10.2.4
- dilxztech@1.0.0
- po-ops-local-dev@99.9.1
- webrix-docs1@10.2.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.