logo

Malicious npm Package “pino-sdk-v2” Caught Harvesting Secrets

ID: e69f3559-c96c-5880-8232-1945384cc8a4

STIX ID: report--e69f3559-c96c-5880-8232-1945384cc8a4

Feed Name: securityonline.info

Threat Score
82/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

SafeDep identified a malicious npm package, pino-sdk-v2, that impersonates the popular pino logger and embeds an obfuscated payload which scans .env files for secrets and exfiltrates them to a hardcoded Discord webhook; the code runs on require() to bypass install-time detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.