OpenSSF/OSV advisory MAL-2026-16123 confirms this npm version as malicious. The package impersonates picomatch (name 'pinochiomathm', description copied from picomatch, homepage pointing at github.com/micromatch/picomach). On require, lib/pinochiomathm.js reads lib/parse.ts.map, base64-decodes it into parsetmp.js, and requires it. The decoded module performs an HTTP GET to https://www.jsonkeeper.com/b/V6NBX with a decoded 'x-secret-key' header, AES-256-CBC-decrypts the response using a...
This report applies to pinochiomathm@2.3.5.
2.3.2, 2.3.3, 2.3.4, 2.3.5
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.