VYPR

npm · Malicious package advisory

Malware

keroeltopkkk

GHSA-4cvc-3pxq-6v5f

Malicious code in keroeltopkkk (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.99.99`

## Source: amazon-inspector (2758c1a2619db534fdc8e2981e051769b20641492d12ff984e333446e0c734e3)
The package ships a single server.js that is wired into every npm lifecycle hook (preinstall, install, postinstall, prepare, prepublish, preprepare, postprepare). On npm install the script reads os.hostname() and issues an HTTPS GET to the hardcoded endpoint https://eo8f3m3ho26a0nm.m.pipedream.net/, sending the installer's hostname and the package name as query parameters to an author-controlled pipedream.net webhook collector. The package has no other functionality: package.json carries an empty description, a placeholder ISC license, a name resembling a token, and version 99.99.99 — the canonical shape used to probe whether a private/internal package name resolves against the public npm registry (dependency confusion). The exfiltrated hostname discloses internal build-host or developer-machine identifiers to the beacon operator.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/af486be301974b4c4068b1c7baa77731f37fa05e/osv/malicious/npm/keroeltopkkk/MAL-2026-16336.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/af486be301974b4c4068b1c7baa77731f37fa05e/osv/malicious/npm/keroeltopkkk/MAL-2026-16336.json
- https://www.npmjs.com/package/keroeltopkkk/v/99.99.99
- https://github.com/advisories/GHSA-4cvc-3pxq-6v5f

Compromised versions (1)

  • = 99.99.99

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.