VYPR

npm · Malicious package advisory

Malware

keroeltopgg

GHSA-p3m2-65cv-vjqj

Malicious code in keroeltopgg (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.99.99`

## Source: amazon-inspector (52b4e331f9f02f436e01e5c7696088d12ea3237af7fbe54fd37ec37e786c960d)
[email protected] is a stub package whose index.js, executed on require/import, reads os.hostname() and issues an HTTPS GET to the hardcoded collector https://eo8f3m3ho26a0nm.m.pipedream.net/ with the package name and hostname as query parameters. The manifest has no real functionality: empty description, no README, version 99.99.99 (the canonical dependency-confusion probe version), duplicate 'Dependencies'/'dependencies' keys, and lifecycle scripts that only echo marker strings. The sole runtime behavior is the outbound beacon to an author-controlled Pipedream endpoint, which reports successful internal-namespace resolution and leaks the installer's hostname to the operator.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/af486be301974b4c4068b1c7baa77731f37fa05e/osv/malicious/npm/keroeltopgg/MAL-2026-16334.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/af486be301974b4c4068b1c7baa77731f37fa05e/osv/malicious/npm/keroeltopgg/MAL-2026-16334.json
- https://www.npmjs.com/package/keroeltopgg/v/99.99.99
- https://github.com/advisories/GHSA-p3m2-65cv-vjqj

Compromised versions (1)

  • = 99.99.99

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.