VDB
Sign up

MAL-2026-16334

Malicious code in keroeltopgg (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (52b4e331f9f02f436e01e5c7696088d12ea3237af7fbe54fd37ec37e786c960d) keroeltopgg@99.99.99 is a stub package whose index.js, executed on require/import, reads os.hostname() and issues an HTTPS GET to the hardcoded collector https://eo8f3m3ho26a0nm.m.pipedream.net/ with the package name and hostname as query parameters. The manifest has no real functionality: empty description, no README, version 99.99.99 (the canonical dependency-confusion probe version), duplicate 'Dependencies'/'dependencies' keys, and lifecycle scripts that only echo marker strings. The sole runtime behavior is the outbound beacon to an author-controlled Pipedream endpoint, which reports successful internal-namespace resolution and leaks the installer's hostname to the operator.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keroeltopgg

No fixed version published yet for keroeltopgg (npm). Pin to a known-safe version or switch to an alternative.

References