LWA-2026-6323 MAL-2026-6794 ↗ confirmed malware

zod-pino434@1.0.127

Malicious code in zod-pino434 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1543.002 · Systemd ServiceT1547.001 · Registry Run Keys / Startup FolderT1564.001 · Hidden Files and DirectoriesT1082 · System Information DiscoveryT1115 · Clipboard DataT1056.001 · KeyloggingT1113 · Screen CaptureT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

Package zod-pino434@1.0.127 is a trojanized clone of the legitimate forge-jsx Autodesk Forge integration tool, published under a combosquat name. On npm install, the postinstall hook runs a chain of scripts that spawn a detached background agent process. This agent connects to an encrypted WebSocket command-and-control relay (host embedded as AES-256-GCM ciphertext with an XOR-obfuscated decryption key). The agent captures clipboard contents, logs keystrokes (via uiohook-napi), takes periodic screenshots, reads local filesystem contents, harvests browser extension databases, and collects Discord bot tokens. Collected data is exfiltrated over the WebSocket C2 channel, via Discord webhooks, and through HuggingFace uploads. The agent persists across reboots by registering OS autostart entries and maintaining a hidden runtime directory under .forge-jsxy/. The package has no repository URL or verifiable publisher identity.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 05:59 PM
analyzed
Jul 4, 2026, 06:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.