LWA-2026-4587 confirmed malware

pino-pretty-logger@1.1.1

Malicious code in pino-pretty-logger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1098.004 · SSH Authorized KeysT1005 · Data from Local System

Analysis

Combosquat of the legitimate pino-pretty package. On require() it auto-executes a multi-function infostealer and backdoor: (1) beacons system info (OS, IPs, username) to coreagnar[.]me/api/validate/system-info; (2) reads .env from the project directory and posts it; (3) recursively scans the filesystem for wallet/credential JSON files, .env files, and credential-related documents, then uploads them; (4) steals the Telegram Desktop tdata directory for session hijacking; (5) on Linux, installs a hardcoded SSH public key into ~/.ssh/authorized_keys for persistent remote access.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 08:22 AM
analyzed
Jun 12, 2026, 08:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.