logs-bin@3.11.11
Malicious code in logs-bin (npm)
Analysis
logs-bin@3.11.11 is a bait-and-switch package: its README describes an error-handling utility (catchAsync, catchCallback) and the name claims to print logs, but the code actually exports GlobalKeyboardListener, a cross-platform keylogger. It spawns bundled native key-capture executables (MacKeyServer Mach-O, WinKeyServer.exe, X11KeyServer, a ~75MB Ntkey.exe) via child_process.execFile and uses sudo-prompt to chmod the binaries with escalated privileges. The repository domain (logs-bin[.]com) is non-GitHub and suspicious and the README is a complete decoy — a disguised keylogger shipped under a misleading identity.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:13 AM
- analyzed
- Jun 10, 2026, 10:15 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.