Malicious npm Package “pino-sdk-v2” Caught Harvesting Secrets
ID: e69f3559-c96c-5880-8232-1945384cc8a4
STIX ID: report--e69f3559-c96c-5880-8232-1945384cc8a4
Feed Name: securityonline.info
Threat Score
SafeDep identified a malicious npm package, pino-sdk-v2, that impersonates the popular pino logger and embeds an obfuscated payload which scans .env files for secrets and exfiltrates them to a hardcoded Discord webhook; the code runs on require() to bypass install-time detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
