Malicious npm Package js-logger-pack Ships a Multi-Platform WebSocket Stealer

2026-04-15 Safe Dep

https://safedep.io/malicious-js-logger-pack-npm-stealer/

Thumbnail for Malicious npm Package js-logger-pack Ships a Multi-Platform WebSocket Stealer

A malicious npm package named js-logger-pack evolved from harmless probes into a full multi-platform infostealer and later a HuggingFace-hosted binary dropper. Weaponized versions installed a Linux SSH backdoor, exfiltrated Telegram Desktop sessions, stole developer and cloud credentials, targeted 27 crypto wallets, scanned sensitive files, streamed native keylogger data, and established persistence on Windows, macOS, and Linux. The operation used api-sub.jrodacooker.dev and 195.201.194.107:8010 for C2, with later versions downloading MicrosoftSystem64 binaries from a HuggingFace repository. The report does not attribute the activity to a known actor, but leaked source exposed the handle and host comment bink@DESKTOP-N8JGD6T.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://195.201.194.107:8010 2026-05-29 2026-05-29
IPv4 195.201.194.107 2025-04-15 2026-05-29
DOMAIN copilot-ai.whisdev.org 2026-05-28 2026-05-28
DOMAIN api-sub.jrodacooker.dev 2025-04-15 2026-04-29

Related Reports

« Back