VDB
Sign up

MAL-2026-16336

Malicious code in keroeltopkkk (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2758c1a2619db534fdc8e2981e051769b20641492d12ff984e333446e0c734e3) The package ships a single server.js that is wired into every npm lifecycle hook (preinstall, install, postinstall, prepare, prepublish, preprepare, postprepare). On npm install the script reads os.hostname() and issues an HTTPS GET to the hardcoded endpoint https://eo8f3m3ho26a0nm.m.pipedream.net/, sending the installer's hostname and the package name as query parameters to an author-controlled pipedream.net webhook collector. The package has no other functionality: package.json carries an empty description, a placeholder ISC license, a name resembling a token, and version 99.99.99 — the canonical shape used to probe whether a private/internal package name resolves against the public npm registry (dependency confusion). The exfiltrated hostname discloses internal build-host or developer-machine identifiers to the beacon operator.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keroeltopkkk

No fixed version published yet for keroeltopkkk (npm). Pin to a known-safe version or switch to an alternative.

References