LWA-2026-6326 MAL-2026-6794 ↗ confirmed malware

zod-pino434@1.0.128

Malicious code in zod-pino434 (npm)

T1059 · Command and Scripting Interpreter

Analysis

Combosquat package impersonating the popular zod and pino libraries. On npm install, the postinstall chain (5 scripts) deploys a persistent remote access trojan: it spawns a detached background Node.js agent process, copies itself to a hidden durable runtime directory under ~/.forge-jsxy/runtime/, registers OS autostart for persistence across reboots, and connects via WebSocket to a remote C2 host (decrypted from AES-256-GCM encrypted configuration at runtime). The agent provides full file system read/write access, clipboard monitoring, secret/credential scanning, Discord webhook/screenshot capabilities, and remote control via WebRTC. The package has no repository and no verifiable publisher identity.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 04:17 AM
analyzed
Jul 5, 2026, 04:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.