LWA-2026-12372 MAL-2026-16484 ↗ confirmed malware

pino-testkit@10.4.5

Malicious code in pino-testkit (npm)

Analysis

Injected backdoor confirmed by direct source inspection. The package is a combosquat of pino (publisher k.dev1949, not the real maintainers) that ships a heavily obfuscated payload in lib/contract.js and wires it into the module's main entry point. Specifically: (1) lib/contract.js uses a shuffle-based deobfuscator whose OUN resolves to 'constructor', then builds and executes a large payload via Function('', ...) with nested Function-constructor invocations (cMp(7746)), a classic obfuscated code-execution pattern; it also sets global['object']=require and global['module']=module to give the payload access to require. (2) pino.js has been modified from the legitimate pino source: it adds `const contract = require('./lib/contract')`, a `chain()` function that calls `contract()`, and critically `module.exports = chain` which OVERRIDES the main export so that `require('pino-testkit')` returns chain — merely invoking the module triggers the obfuscated payload. The real pino package has no lib/contract.js and no chain function. (3) The detonation sandbox observed a DNS sinkhole query to _leitwacht.attached.local. (German for "command/control room"), consistent with a C2 beacon from the executed payload. The first agent's benign verdict was wrong: it focused on lifecycle hooks and network markers but missed the obfuscated payload file and the main-export override. This is a genuine supply-chain backdoor with no credible benign explanation.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 08:20 PM
analyzed
Sep 23, 2026, 08:23 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.