SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is a malware due to system info exfiltration via DNS/HTTPS to OAST domains and arbitrary code execution during preinstall.

Verification Record

The package is marked as malware by OSV: MAL-2026-2653 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package is a malware because it exhibits multiple malicious behaviors. It collects system information (hostname, username, current working directory, platform details, environment variables) and exfiltrates it to external servers via DNS and HTTPS requests. The domains used for exfiltration, ienfcixqbgvbxkccdoxgfz2zhmspdpiys.oast.fun and www.mygoals.live, are associated with OAST (Out-of-band Application Security Testing), suggesting malicious intent. Furthermore, the package includes a preinstall script that executes node index.js, allowing arbitrary code execution upon installation. These multiple pieces of evidence strongly indicate that this package is malicious.

pinlogger@99.0.0Malicious
Verified
Analysed at: 4/11/26, 5:51 PM
Source: https://registry.npmjs.org/pinlogger/-/pinlogger-99.0.0.tgz
SHA256: 82c31a709910d8a216297ee44a76476d94cbe55108aaa9e28c29ba7520526438
Confidence: High