LWA-2026-12106 MAL-2026-16154 ↗ confirmed malware

pino-ulid@2.12.3

Malicious code in pino-ulid (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1547.001 · Registry Run Keys / Startup FolderT1543.002 · Systemd ServiceT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

pino-ulid is a combosquat of the legitimate ulid package that ships cloned ULID code alongside a full remote-control agent. Its postinstall hook runs dist/node/utils.js, which spawns a detached background node process executing dist/node/payload.js. That payload fingerprints the host (Windows MachineGuid, macOS IOPlatformUUID, Linux /etc/machine-id), installs persistence (Windows schtasks/registry Run key, macOS launchd, Linux systemd user service or ~/.config/autostart), and opens a WebSocket connection to an XOR-obfuscated C2 endpoint at ws://95[.]216[.]232[.]16:8010/ (HTTP fallback hxxp://95[.]216[.]232[.]16:8010/). It sends a hello/heartbeat with a unique agent id and accepts remote tasks including list_dir, list_drives, deploy_binary (download and execute an arbitrary binary supplied by the controller), and remove_agent.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 08:58 AM
analyzed
Sep 14, 2026, 09:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.