MAL-2026-16334
Malicious code in keroeltopgg (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (52b4e331f9f02f436e01e5c7696088d12ea3237af7fbe54fd37ec37e786c960d) keroeltopgg@99.99.99 is a stub package whose index.js, executed on require/import, reads os.hostname() and issues an HTTPS GET to the hardcoded collector https://eo8f3m3ho26a0nm.m.pipedream.net/ with the package name and hostname as query parameters. The manifest has no real functionality: empty description, no README, version 99.99.99 (the canonical dependency-confusion probe version), duplicate 'Dependencies'/'dependencies' keys, and lifecycle scripts that only echo marker strings. The sole runtime behavior is the outbound beacon to an author-controlled Pipedream endpoint, which reports successful internal-namespace resolution and leaks the installer's hostname to the operator.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for keroeltopgg (npm). Pin to a known-safe version or switch to an alternative.