LWA-2026-11658 confirmed malware

eth-pino@2.0.3

Malicious code in eth-pino (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

eth-pino@2.0.3, a combosquat of the pino logger, exfiltrates the installer's environment and executes remote code on load. Requiring the package runs lib/initializeCaller.js, which base64-decodes the URL hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df and POSTs the entire process.env (all environment variables, including credentials and tokens) to it. It then takes the HTTP response body and executes it as JavaScript via the Function constructor with require in scope, enabling arbitrary remote second-stage code execution on the victim machine.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 09:39 AM
analyzed
Aug 27, 2026, 09:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.