Malicious code in pinno-loggers (npm)
pinno-loggers is a malicious npm package that depends on terminal-logger-utils and executes a multi-stage malware payload via postinstall hooks. The second-stage binary provides keylogger, infostealer, and RAT capabilities, stealing sensitive data including credentials, SSH keys, and crypto wallets.
- Disclosed
- Last updated
- Blast radius
- Any developer or system that installed or imported the pinno-loggers package
- Ecosystems
- Attack vectors
- Affected entities
- pinno-loggersMalicious npm package with dependency on terminal-logger-utils
pinno-loggers is a malicious npm package discovered in the OpenSSF malicious packages repository. The package depends on terminal-logger-utils, which contains the primary malicious payload.
Upon installation or import, a postinstall hook is triggered that executes utils.cjs, an obfuscated malware dropper. This dropper downloads and executes a platform-specific second-stage binary hosted on Hugging Face.
The second-stage payload provides keylogger, infostealer, and remote access trojan (RAT) functionality. It exfiltrates sensitive local data including Telegram Desktop sessions, browser login databases, cryptocurrency wallets, SSH keys, cloud configurations, environment variables, and files matching specific keywords. The malware establishes a connection to a remote command-and-control server for full machine control.
This incident was identified and credited to the OpenSSF malicious packages project.
Indicators of compromise
- Packages
- pinno-loggers
- terminal-logger-utils
Remediation
- Immediately uninstall pinno-loggers and terminal-logger-utils from all systems
- Audit npm package.json and lock files for presence of these packages across all projects
- Regenerate all sensitive credentials including SSH keys, API tokens, and cloud credentials
- Scan systems for indicators of compromise including network connections to unknown C2 servers
- Review browser login databases and cryptocurrency wallet access logs for unauthorized activity
- Check Telegram Desktop and other messaging applications for unauthorized access
- Monitor for suspicious postinstall hook execution in npm audit logs
- Use npm audit to identify any remaining malicious dependencies
- Consider using npm package signing verification and supply chain security tools
Sources
- GitHub Advisory GHSA-hxwm-gvm7-fq2q · GitHub Advisory Database
Cite this entry
"Malicious code in pinno-loggers (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/malicious-code-in-pinno-loggers-npm-11x34i
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g2-ssr (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-basic (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit