Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Malware in pinokio-redis

Malware discovered in the npm package pinokio-redis. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with the package installed or running
Ecosystems
Attack vectors
Affected entities
  • pinokio-redisnpm package containing malware

The npm package pinokio-redis has been identified as containing malware. According to the GitHub Advisory (GHSA-3gfp-7x5j-mp63), any computer with this package installed or running should be considered fully compromised.\n\nThe advisory recommends immediate rotation of all secrets and keys stored on affected systems, performed from a different, uncompromised computer. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the package installation, given the potential for full system compromise.\n\nAffected users should treat their systems as potentially under external control and take appropriate security measures accordingly.

Indicators of compromise

Packages
  • pinokio-redis

Remediation

  • Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer
  • Remove the pinokio-redis package from all affected systems
  • Perform a full security audit and malware scan on any system that had the package installed
  • Consider the affected system(s) as potentially compromised and plan for full rebuild or replacement if critical systems are involved
  • Review access logs and monitor for unauthorized activity on systems that had this package installed

Sources

  1. GitHub Advisory GHSA-3gfp-7x5j-mp63 · GitHub Advisory Database

Cite this entry

"Malware in pinokio-redis." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 7, 2026; last updated July 7, 2026. https://supplychainattack.org/incident/malware-in-pinokio-redis-1vali5

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in typescirpt-core (npm)

    The npm package 'typescirpt-core' (a typosquat of 'typescript') contained malicious code that executed on install, downloading and executing a Windows executable and pivoting WSL environments back to the host Windows system.

    npmTyposquattingCompromised package
  2. containedcritical

    Malicious code in typescrit-cli (npm)

    The npm package typescrit-cli contained malicious postinstall code that downloads and executes a payload, with capability to escape WSL containers and compromise Windows hosts. The package name is a typosquat of the legitimate typescript-cli.

    npmTyposquattingCompromised package
  3. containedcritical

    Malicious code in typesript-cli (npm)

    The npm package 'typesript-cli' (a one-character typosquat of 'typescript') contains malicious code in its postinstall script that downloads and executes a Windows PE binary, and can cross the Linux/WSL sandbox boundary to execute payloads on the Windows host. The script also beacons to a hardcoded IP endpoint.

    npmTyposquattingCompromised package
  4. containedcritical

    Malicious code in testingsmthb1g (npm)

    The npm package testingsmthb1g contains malicious code in its postinstall script that acts as an install-time dropper, downloading and executing a Windows binary payload and exfiltrating platform information. The attack includes sandbox escape capabilities for WSL/virtualized Linux environments.

    npmCompromised package