pino-pretty-logger@1.1.1
Malicious code in pino-pretty-logger (npm)
Analysis
Combosquat of the legitimate pino-pretty package. On require() it auto-executes a multi-function infostealer and backdoor: (1) beacons system info (OS, IPs, username) to coreagnar[.]me/api/validate/system-info; (2) reads .env from the project directory and posts it; (3) recursively scans the filesystem for wallet/credential JSON files, .env files, and credential-related documents, then uploads them; (4) steals the Telegram Desktop tdata directory for session hijacking; (5) on Linux, installs a hardcoded SSH public key into ~/.ssh/authorized_keys for persistent remote access.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 08:22 AM
- analyzed
- Jun 12, 2026, 08:24 AM
Related advisories
- packageuwu@1.0.1
- ndmckauxuoincv@1.0.0
- npmscript_tesstalert_unpkg@1.0.1
- my-ctf-helper-script-9921@1.0.0
- pflag14570@1.0.0
- pf23727@1.0.0
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.