pinokio-redis@1.0.127
Malicious code in pinokio-redis (npm)
Analysis
pinokio-redis@1.0.127 is a combosquat package (the real "pinokio" name with "-redis" appended) that installs a persistent surveillance agent on the victim's machine. The postinstall chain runs five scripts that register OS autostart (systemd on Linux, LaunchAgent on macOS, registry/startup on Windows) and spawn a background agent process. The agent captures keystrokes via uiohook-napi, monitors clipboard content, takes screenshots, and performs a full filesystem scan for cryptocurrency wallet keys (BIP39 mnemonics, secp256k1 private keys, Solana keypair JSON files), SSH private keys, and AWS credentials. It also harvests Chromium browser extension LevelDB databases (targeting MetaMask, Phantom, and other crypto wallet extensions). Stolen secrets are written to a hidden vault directory under the CfgMgr data directory and exfiltrated to Hugging Face Hub repositories (agents/<hostname>/result.json) and via Discord webhooks. The agent communicates with a relay server over WebSocket, with the relay host encrypted in the package using AES-256-GCM with an XOR-obfuscated embedded key.
- analyzed by
- Leitwacht
- first seen
- Jul 6, 2026, 05:48 AM
- analyzed
- Jul 6, 2026, 05:49 AM
Related advisories
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- crypto-base58@1.0.1
- pino-zod@1.0.121
- zod-pino@1.0.122
- nat-ulid@3.0.2
- seed-to-private@1.0.1
- prettier-lint-lenz@2.6.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.