pampipes@1.1.9
Malicious code in pampipes (npm)
Analysis
pampipes@1.1.9 is a combosquat of the pino logger (main file pino.js, homepage getpino[.]io) whose actual code is unrelated. lib/writer.js, required at top level, runs on require(): it collects all process.env variables, hostname, OS username, platform, and MAC addresses, then makes a remote HTTP GET and evals the response body, giving the C2 arbitrary code execution in the installer's context. Two C2 endpoints are configured: a base64-encoded coingecko-liard[.]vercel[.]app/api/data and a hex-encoded jsonkeeper[.]com/b/HY6M6. The package ships no working logging functionality and is entirely an env-harvesting plus remote-eval implant.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 12:44 AM
- analyzed
- Jun 12, 2026, 12:46 AM
Related advisories
- coral-wraith@1.0.4
- operni@1.2.7
- oprnm@1.0.0
- internallib_v557@1.0.5
- worker-build@9.0.1
- index-ulid@3.0.2
- npm-scanner@1.0.0
- npmjs-doc-builder@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.