LWA-2026-6345 MAL-2026-6938 ↗ confirmed malware

pinokio-redis@1.0.127

Malicious code in pinokio-redis (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1543.002 · Systemd ServiceT1547.001 · Registry Run Keys / Startup FolderT1056.001 · KeyloggingT1115 · Clipboard DataT1113 · Screen CaptureT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

pinokio-redis@1.0.127 is a combosquat package (the real "pinokio" name with "-redis" appended) that installs a persistent surveillance agent on the victim's machine. The postinstall chain runs five scripts that register OS autostart (systemd on Linux, LaunchAgent on macOS, registry/startup on Windows) and spawn a background agent process. The agent captures keystrokes via uiohook-napi, monitors clipboard content, takes screenshots, and performs a full filesystem scan for cryptocurrency wallet keys (BIP39 mnemonics, secp256k1 private keys, Solana keypair JSON files), SSH private keys, and AWS credentials. It also harvests Chromium browser extension LevelDB databases (targeting MetaMask, Phantom, and other crypto wallet extensions). Stolen secrets are written to a hidden vault directory under the CfgMgr data directory and exfiltrated to Hugging Face Hub repositories (agents/<hostname>/result.json) and via Discord webhooks. The agent communicates with a relay server over WebSocket, with the relay host encrypted in the package using AES-256-GCM with an XOR-obfuscated embedded key.

analyzed by
Leitwacht
first seen
Jul 6, 2026, 05:48 AM
analyzed
Jul 6, 2026, 05:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.