pino-ulid@2.12.3
Malicious code in pino-ulid (npm)
Analysis
pino-ulid is a combosquat of the legitimate ulid package that ships cloned ULID code alongside a full remote-control agent. Its postinstall hook runs dist/node/utils.js, which spawns a detached background node process executing dist/node/payload.js. That payload fingerprints the host (Windows MachineGuid, macOS IOPlatformUUID, Linux /etc/machine-id), installs persistence (Windows schtasks/registry Run key, macOS launchd, Linux systemd user service or ~/.config/autostart), and opens a WebSocket connection to an XOR-obfuscated C2 endpoint at ws://95[.]216[.]232[.]16:8010/ (HTTP fallback hxxp://95[.]216[.]232[.]16:8010/). It sends a hello/heartbeat with a unique agent id and accepts remote tasks including list_dir, list_drives, deploy_binary (download and execute an arbitrary binary supplied by the controller), and remove_agent.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 08:58 AM
- analyzed
- Sep 14, 2026, 09:02 AM
Related advisories
- map-streak-kit@1.0.0
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- entropyeasybots@2.0.2
- streak-metrics-math@1.0.1
- streak-math-metrics@1.0.0
- system-performance-helper@1.0.1
- json-validator-utils@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.