pino-pretty-logger@1.1.1
Malicious code in pino-pretty-logger (npm)
Analysis
Combosquat of the legitimate pino-pretty package. On require() it auto-executes a multi-function infostealer and backdoor: (1) beacons system info (OS, IPs, username) to coreagnar[.]me/api/validate/system-info; (2) reads .env from the project directory and posts it; (3) recursively scans the filesystem for wallet/credential JSON files, .env files, and credential-related documents, then uploads them; (4) steals the Telegram Desktop tdata directory for session hijacking; (5) on Linux, installs a hardcoded SSH public key into ~/.ssh/authorized_keys for persistent remote access.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 08:22 AM
- analyzed
- Jun 12, 2026, 08:24 AM
Related advisories
- packageuwu@1.0.1
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
- parket-helper@0.0.1
- textdecode@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.