zod-pino434@1.0.128
Malicious code in zod-pino434 (npm)
Analysis
Combosquat package impersonating the popular zod and pino libraries. On npm install, the postinstall chain (5 scripts) deploys a persistent remote access trojan: it spawns a detached background Node.js agent process, copies itself to a hidden durable runtime directory under ~/.forge-jsxy/runtime/, registers OS autostart for persistence across reboots, and connects via WebSocket to a remote C2 host (decrypted from AES-256-GCM encrypted configuration at runtime). The agent provides full file system read/write access, clipboard monitoring, secret/credential scanning, Discord webhook/screenshot capabilities, and remote control via WebRTC. The package has no repository and no verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 04:17 AM
- analyzed
- Jul 5, 2026, 04:39 AM
Related advisories
- zod-pino434@1.0.127 same package
- paperclip2@1.0.0
- chai-redirection@0.0.1
- vps-maintenance-paperclip-adapter@0.1.1
- express-ini@12.1.10
- compose-logger-stand@1.0.126
- chain-chai-await@1.3.5
- chain-chai-async@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.