{"id":"MAL-2026-16334","summary":"Malicious code in keroeltopgg (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (52b4e331f9f02f436e01e5c7696088d12ea3237af7fbe54fd37ec37e786c960d)\nkeroeltopgg@99.99.99 is a stub package whose index.js, executed on require/import, reads os.hostname() and issues an HTTPS GET to the hardcoded collector https://eo8f3m3ho26a0nm.m.pipedream.net/ with the package name and hostname as query parameters. The manifest has no real functionality: empty description, no README, version 99.99.99 (the canonical dependency-confusion probe version), duplicate 'Dependencies'/'dependencies' keys, and lifecycle scripts that only echo marker strings. The sole runtime behavior is the outbound beacon to an author-controlled Pipedream endpoint, which reports successful internal-namespace resolution and leaks the installer's hostname to the operator.\n","modified":"2026-09-21T04:00:07.699747042Z","published":"2026-09-21T03:32:35Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["99.99.99"],"id":"IN-MAL-2026-020242","import_time":"2026-09-21T03:46:39.173996081Z","modified_time":"2026-09-21T03:32:35Z","sha256":"52b4e331f9f02f436e01e5c7696088d12ea3237af7fbe54fd37ec37e786c960d"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/keroeltopgg/v/99.99.99"}],"affected":[{"package":{"name":"keroeltopgg","ecosystem":"npm","purl":"pkg:npm/keroeltopgg"},"versions":["99.99.99"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"8e7ddf1ccd1d91e85eb60403b8d0d0461ba2466d6cade49a82622232bb5faa7b","tlsh":"83d0a7c703d5b3906ae18cc0e0260607674af13771a845b8a14c93954de38a105a35c0"},{"sha256":"bdabd9f9e237455441709ffde29f4a2d7f67f70eedc0580b2f014388947164dd","tlsh":"6b01c8b35c586f3278b925b619606562fb601f27aa26880af8f7472f0bdad228015e54","path":"package.json"}],"package_integrity":[{"filename":"keroeltopgg-99.99.99.tgz","hashes":{"sha512_sri":"sha512-vLrJ4LGTxawVmWSIpBVcd7HSLw1w0YjOuUw79brp5g8SvrR5XiidBMY3Mjbt4g8jAqQEuaN1wKttiwjbJ7YCCA==","sha1":"dd245c435c7d2159daea63df853e2af5d1c2eb04"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/keroeltopgg/MAL-2026-16334.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}