zod-pino434@1.0.127
Malicious code in zod-pino434 (npm)
Analysis
Package zod-pino434@1.0.127 is a trojanized clone of the legitimate forge-jsx Autodesk Forge integration tool, published under a combosquat name. On npm install, the postinstall hook runs a chain of scripts that spawn a detached background agent process. This agent connects to an encrypted WebSocket command-and-control relay (host embedded as AES-256-GCM ciphertext with an XOR-obfuscated decryption key). The agent captures clipboard contents, logs keystrokes (via uiohook-napi), takes periodic screenshots, reads local filesystem contents, harvests browser extension databases, and collects Discord bot tokens. Collected data is exfiltrated over the WebSocket C2 channel, via Discord webhooks, and through HuggingFace uploads. The agent persists across reboots by registering OS autostart entries and maintaining a hidden runtime directory under .forge-jsxy/. The package has no repository URL or verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 05:59 PM
- analyzed
- Jul 4, 2026, 06:02 PM
Related advisories
- zod-pino434@1.0.128 same package
- crypto-base58@1.0.1
- pino-zod@1.0.121
- zod-pino@1.0.122
- nat-ulid@3.0.2
- seed-to-private@1.0.1
- prettier-lint-lenz@2.6.4
- hex-type@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.