Malicious npm Package js-logger-pack Ships a Multi-Platform WebSocket Stealer
2026-04-15 • Safe Dep •
A malicious npm package named js-logger-pack evolved from harmless probes into a full multi-platform infostealer and later a HuggingFace-hosted binary dropper. Weaponized versions installed a Linux SSH backdoor, exfiltrated Telegram Desktop sessions, stole developer and cloud credentials, targeted 27 crypto wallets, scanned sensitive files, streamed native keylogger data, and established persistence on Windows, macOS, and Linux. The operation used api-sub.jrodacooker.dev and 195.201.194.107:8010 for C2, with later versions downloading MicrosoftSystem64 binaries from a HuggingFace repository. The report does not attribute the activity to a known actor, but leaked source exposed the handle and host comment bink@DESKTOP-N8JGD6T.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://195.201.194.107:8010 | 2026-05-29 | 2026-05-29 |
| IPv4 | 195.201.194.107 | 2025-04-15 | 2026-05-29 |
| DOMAIN | copilot-ai.whisdev.org | 2026-05-28 | 2026-05-28 |
| DOMAIN | api-sub.jrodacooker.dev | 2025-04-15 | 2026-04-29 |