Malicious npm Package Exfiltrates Secrets via Discord Webhook

A malicious npm package named pino-sdk-v2 was discovered posing as the pino logging library.

Pulse ID: 69b5d61883ee4f64624dabd1
Pulse Link: https://otx.alienvault.com/pulse/69b5d61883ee4f64624dabd1
Pulse Author: cryptocti
Created: 2026-03-14 21:41:44

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Discord #InfoSec #NPM #OTX #OpenThreatExchange #RAT #bot #cryptocti

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange