LWA-2026-4502 MAL-2026-5872 ↗ confirmed malware

pampipes@1.1.9

Malicious code in pampipes (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

pampipes@1.1.9 is a combosquat of the pino logger (main file pino.js, homepage getpino[.]io) whose actual code is unrelated. lib/writer.js, required at top level, runs on require(): it collects all process.env variables, hostname, OS username, platform, and MAC addresses, then makes a remote HTTP GET and evals the response body, giving the C2 arbitrary code execution in the installer's context. Two C2 endpoints are configured: a base64-encoded coingecko-liard[.]vercel[.]app/api/data and a hex-encoded jsonkeeper[.]com/b/HY6M6. The package ships no working logging functionality and is entirely an env-harvesting plus remote-eval implant.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 12:44 AM
analyzed
Jun 12, 2026, 12:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.