Malware detected: Exfiltrates .env file keys to Discord webhook. Impersonates legit pino package with modified malicious package/lib/tools.js.
-= Per source details. Do not edit below this line.=-
The package pino-sdk-v2 was found to contain malicious code.
{
"malicious-packages-origins": [
{
"sha256": "093fa98258b33a735216506ea119532a3cc24c92359028b4bb1955d0b712951a",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"source": "amazon-inspector",
"import_time": "2026-03-08T01:37:56.249636634Z",
"modified_time": "2026-03-08T01:35:03Z"
}
]
}