OpenSSF/OSV advisory MAL-2026-16154 confirms this npm version as malicious. pino-ulid impersonates the popular `pino` and `ulid` packages (homepage points at github.com/ulid/javascript) and ships a genuine ULID code path as cover. The package.json `postinstall` hook runs `node dist/node/utils.js`, which spawns `dist/node/payload.js` detached with stdio ignored and unref'd, gated by a minimum CPU-count check (sandbox evasion) and a prior-install check against schtasks / HKCU Run / launchd /...
This report applies to pino-ulid@2.12.3.
2.12.3, 2.12.2
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.