-= Per source details. Do not edit below this line.=-
The package impersonates the pino logger (README assets, keywords, and internal filenames such as lib/proto.js, lib/multistream.js, lib/redaction.js, lib/transport.js, lib/writer.js are pino-branded) but its declared purpose is unrelated. On require, index.js loads lib/writer.js, which builds an object containing the full process.env, os.platform(), os.hostname(), os.userInfo().username, and non-internal MAC addresses, then unconditionally invokes context.data() from lib/content.js. That function issues an axios GET to https://pro-api.coinmarketcap.com/public-api/v1/ and eval()s a heavily obfuscated string (obfuscator.io-style string array with base64/XOR/RC4 decoders) that reconstructs a JSON-RPC eth_call transport, XOR-decodes the response, and spawns a child process using process.execPath to execute the retrieved payload. lib/writer.js additionally contains a hex-encoded fallback loader decoding to https://www.jsonkeeper.com/b/HY6M6. lib/content.js is heavily obfuscated (while(!![]), array-shift decoder) to hide the destinations and payload from review.
{
"malicious-packages-origins": [
{
"import_time": "2026-07-13T15:30:30.888623176Z",
"sha256": "49e38202e2579f6591dbc161817859bb99a212cbf6c1e5482b3271acf8fc4de0",
"modified_time": "2026-07-13T14:20:42Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-010258",
"versions": [
"1.7.13"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/auth-gen-next/MAL-2026-10449.json"
{
"evidence_files": [
{
"sha256": "73ac5a03c700b28d5db8b03c3b4c8dc7377e1f468f4c983111666fcdfb90ba73",
"path": "lib/content.js",
"tlsh": "38d2c8c93bd2f0a01222a0bb7d1b65a5e1359c89b3ccc088f7a6f458fd58758e179f54"
},
{
"sha256": "c8c0475aed9beb3f7d0a161ab916b85a56cc5bd0df05c7d7bf337e5f8729185d",
"tlsh": "942102b19792a41022301be248db4460bbd1f3553196405cb9fc86ca1bf3dd17155fb4",
"path": "lib/writer.js"
},
{
"sha256": "ffbdd61ea2a24056a212afd80208afce032cd0403a246f1218266e375102d76a",
"path": "package.json",
"tlsh": "5d019c50cd25aea344c92593582a51876761cc5b5818fc2c33c7a36d0f5d57f15ff29c"
}
],
"package_integrity": [
{
"filename": "auth-gen-next-1.7.13.tgz",
"hashes": {
"sha1": "38c22a054db80caf480a4328e9fd9cbd1be187f1",
"sha512_sri": "sha512-GY8Rjv+mBw5PUzYbUf5aNA85iEBIqZEsOSihM7rLfSPNW+SNm9QjwO978lwZ+y5Q8+g5Vt3aa+yliomFlsRH2A=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]