-= Per source details. Do not edit below this line.=-
Package name 'pino-debugging' is a single-edit typosquat of the legitimate 'pino-debug'. The shipped index.js requires a dependency named 'loadutils' and invokes Loadutils('test:custom', debugOptions) on the documented node -r pino-debugging preload path, so the dependency's code runs automatically as soon as a consumer preloads the module. A PUBLISHGUIDE.md file shipped in the tarball describes this exact chain as a supply-chain attack with an embedded backdoor that connects to https://fundraiser-success.vercel.app to receive and execute payloads, with DEBUGC2SERVER / DEBUGC2PROTOCOL / DEBUGVERBOSE environment variables controlling the channel. The package.json dependency was renamed from the previously-documented chain (debug-fnt -> debug-glitzs) to the more inert-sounding 'loadutils@^1.0.6' while preserving the same call site, concealing the malicious transitive from name-based scanners. Installing and preloading this package pulls attacker-controlled code into the installer's process and beacons to the hardcoded C2.
{
"malicious-packages-origins": [
{
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"import_time": "2026-06-29T07:09:11.057165316Z",
"id": "IN-MAL-2026-007766",
"sha256": "2f34694171d099a29f77430359b02afb82c2333967feb1ec6e0bd845b98244b9",
"modified_time": "2026-06-29T06:27:33Z",
"source": "amazon-inspector",
"versions": [
"1.1.3"
]
},
{
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"import_time": "2026-06-29T07:09:11.000841771Z",
"id": "IN-MAL-2026-007765",
"sha256": "7a1dec01ea37a9f36226fd542dd6dc519bb7e5a398895f29191aec15ac7c9e5f",
"modified_time": "2026-06-29T06:27:23Z",
"source": "amazon-inspector",
"versions": [
"1.1.4"
]
},
{
"import_time": "2026-07-09T17:19:29.411253972Z",
"id": "IN-MAL-2026-009363",
"sha256": "83f0ecc81a618444e701cf5302ced1fa1e92aadc8df2ae2821d2a94a30683d9d",
"modified_time": "2026-07-09T17:01:25Z",
"source": "amazon-inspector",
"versions": [
"1.1.5"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "PUBLISH_GUIDE.md",
"tlsh": "fa0262ba4183e26d0737919bd01cb576ea6fe13f6e82c59cb0bd02282349db9431729d",
"sha256": "44079cad7f5c93e95aa11c6a691672c3c8f2935b5aa12e06d218a7ace9851a1c"
},
{
"path": "index.js",
"tlsh": "f591525839e7f0d26633a7b1c52f2411faba94231136e461f6cc91902fb210452baee9",
"sha256": "07375404832e92c062958515e03544d273c0c2552e933d33238f46d1bddaaf81"
},
{
"path": "CHANGELOG.md",
"tlsh": "88c16478b20b75279397069bd55f32732f79e65ea722102e44ac829c73436b4a36f07c",
"sha256": "1f5ca542b6efdeeddeebde29dc30052d97f96828b268656b5cf3234ffc28af0c"
}
],
"package_integrity": [
{
"filename": "pino-debugging-1.1.3.tgz",
"hashes": {
"sha1": "2d50ff38b7aac4a6a16830f1e803c004042a398a",
"sha512_sri": "sha512-3Vx4D/tXzRa2KDI7uBgOkuGptoMhiqi7894h0pgKeUWLtn/yW8NMrrBHbSSIpjZ/Z6G+9+g34I9Gcx8QbtpNYw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pino-debugging/MAL-2026-6583.json"