AI
Legitimate Pinokio Electron application
Objectives
hostile severity, 95% confident.
supply-chain/trojanized
Node.js package targets credentials for HTTP exfiltration
hostile severity, 95% confident.
supply-chain/trojanized/app
Node.js package targets credentials for HTTP exfiltration
suspicious severity, 100% confident.
anti-static/obfuscation/eval
Generic Function constructor usage
suspicious severity, 97% confident.
collection/activity
React __reactProps$ scraping
suspicious severity, 97% confident.
collection/messaging
Filters messages for 8 hex codes
suspicious severity, 94% confident.
command-and-control/backdoor/tasking
JS execSync command call
suspicious severity, 95% confident.
command-and-control/dropper
ActiveXObject in modern JavaScript (obsolete API)
suspicious severity, 94% confident.
credential-access/env/secrets
Filters process.env for secret values
suspicious severity, 98% confident.
discovery/system/fingerprint
Hybrid environment (Electron/NW.js) profiling with persistence
suspicious severity, 94% confident.
impact/wipe
QNX Node process kill loop
suspicious severity, 95% confident.
impact/wipe/disk
Wiper with HTTP callback
suspicious severity, 95% confident.
supply-chain/recon-exfil
Writes stolen data to HTTP body
Micro-behaviors
suspicious severity, 95% confident.
os/random
Uses Alea PRNG magic constants
Metadata
suspicious severity, 100% confident.
lang/encoded
javascript code encoded in string
20 of 307 traits shown
Identity
| SHA-256 | fc0f17c792e7a1b8904606a047d7a38848d89d00a0ec47b05e29d07e9b5ed3cd |
|---|---|
| Canonical SHA-256 | 000877d1b0f3d96fa96340eacd5e83109ed2166e0698a934c1ed2bd2a5d78e51 |
| Filename | Pinokio-7.2.6-mac.zip |
| Package | pinokio |
Origin
| Source | forager |
|---|---|
| Feed | pinokio |
| Ecosystem | vendor |
| Domain | pinokio.computer |
| URL | https://github.com/pinokiocomputer/pinokio/releases/download/v7.2.6/Pinokio-7.2.6-mac.zip |
Timeline
| First seen | 29 May 2026 21:54 UTC |
|---|---|
| First analyzed | 14 Jun 2026 23:57 UTC |
| Last analyzed | 15 Jun 2026 11:24 UTC |
| Last updated | 16 Jun 2026 15:17 UTC |
Labeling
| Label | good |
|---|---|
| Label source | forager |
| Traits version | 061e3 |
Not seeing what you expected? Let us know