SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malware detected: Exfiltrates .env file keys to Discord webhook. High confidence due to multiple indicators in package/lib/tools.js.

Verification Record

Human analysis confirms that this package is malware.

Details

Note: This report is updated by a verification record

The package pino-sdk-v2 version 9.9.0 is highly likely to be malware. The primary reason is the presence of code in package/lib/tools.js that is designed to extract sensitive information (private keys) from .env files and exfiltrate it to a Discord webhook. This behavior is identified by the LLM-based file evaluation service with medium confidence. Additionally, the YARA rule discord_bot is triggered in the same file, further supporting the malicious intent. Although the YARA rule matches for high entropy in image files are likely false positives, the combination of credential leakage and Discord webhook usage provides strong evidence of malicious activity.

pino-sdk-v2@9.9.0Malicious
Verified
Analysed at: 3/6/26, 4:49 AM
Source: https://registry.npmjs.org/pino-sdk-v2/-/pino-sdk-v2-9.9.0.tgz
SHA256: 07597050ee9500d2d5797cc0f2f99680567f46e1ac1e5e5f85a1cc185815acc9
Confidence: High