nj-logger is a malicious npm package that when imported in file dist/logger/telemetry.js downloads a trojan (for Windows only, W64.AIDetectMalware / Trojan.Malware.300983.susgen) from http://178.128.88[.]40:8080/download/svc to path node_modules/.cache/nj-logger/nj-transport-win32-x64.node and executes it. Downloader is obfuscated as telemetry module, urls & paths are base64 and XOR encoded.
-= Per source details. Do not edit below this line.=-
The package nj-logger was found to contain malicious code.
{
"malicious-packages-origins": [
{
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2026-04-23T20:43:56Z",
"sha256": "35414b2bda6d20336301bfdc5c0147a6434ee0e712f1fd5962a61ef34d6e53e9",
"import_time": "2026-04-23T20:49:04.387597334Z",
"source": "amazon-inspector"
}
],
"iocs": {
"urls": [
"http://178.128.88.40:8080/download/svc"
]
}
}