pino-pretty-logs@1.1.0
Malicious code in pino-pretty-logs (npm)
Analysis
This is a combosquat of the popular pino-pretty logger. Its package main dist/index.js presents a legitimate-looking Logger class as cover but, at module load, executes the bundled malicious payload via a top-level require("./logger"). dist/logger.js (~51KB) is heavily obfuscated javascript-obfuscator output (string-array decoder, _0x identifiers, ~1700 obfuscation hits, String.fromCharCode) that at runtime requires os and fs and reads process.env, consistent with host/environment information-stealer behavior triggered simply by importing the package. The exfiltration endpoint is hidden inside the RC4-style encoded string array and is not recoverable in plaintext, so no network IOC is provided.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 08:22 AM
- analyzed
- Jun 12, 2026, 08:24 AM
Related advisories
- pino-pretty-logger@1.1.1
- pino-formatter@1.1.12
- period-newline@0.1.0
- internallib_v557@1.0.5
- npm-doc-dev@1.0.9
- noon-contracts@1.0.0
- node-gyp-runtime@1.0.0
- node-env-resolve@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.