Open-source atomic malware analysis

Analyze another

Pinokio-7.2.6-mac.zip

ZIP
Verdict: BENIGN
AI Legitimate Pinokio Electron application

Objectives

hostile severity, 95% confident.
supply-chain/trojanized Node.js package targets credentials for HTTP exfiltration
hostile severity, 95% confident.
supply-chain/trojanized/app Node.js package targets credentials for HTTP exfiltration
suspicious severity, 100% confident.
anti-static/obfuscation/eval Generic Function constructor usage
suspicious severity, 97% confident.
collection/activity React __reactProps$ scraping
suspicious severity, 97% confident.
collection/messaging Filters messages for 8 hex codes
suspicious severity, 94% confident.
command-and-control/backdoor/tasking JS execSync command call
suspicious severity, 95% confident.
command-and-control/dropper ActiveXObject in modern JavaScript (obsolete API)
suspicious severity, 94% confident.
credential-access/env/secrets Filters process.env for secret values
suspicious severity, 98% confident.
discovery/system/fingerprint Hybrid environment (Electron/NW.js) profiling with persistence
suspicious severity, 94% confident.
impact/wipe QNX Node process kill loop
suspicious severity, 95% confident.
impact/wipe/disk Wiper with HTTP callback
suspicious severity, 95% confident.
supply-chain/recon-exfil Writes stolen data to HTTP body

Micro-behaviors

suspicious severity, 95% confident.
os/random Uses Alea PRNG magic constants

Metadata

suspicious severity, 100% confident.
lang/encoded javascript code encoded in string

20 of 307 traits shown

Identity

SHA-256 fc0f17c792e7a1b8904606a047d7a38848d89d00a0ec47b05e29d07e9b5ed3cd
Canonical SHA-256 000877d1b0f3d96fa96340eacd5e83109ed2166e0698a934c1ed2bd2a5d78e51
Filename Pinokio-7.2.6-mac.zip
Package pinokio

Origin

Source forager
Feed pinokio
Ecosystem vendor
Domain pinokio.computer
URL https://github.com/pinokiocomputer/pinokio/releases/download/v7.2.6/Pinokio-7.2.6-mac.zip

Timeline

First seen 29 May 2026 21:54 UTC
First analyzed 14 Jun 2026 23:57 UTC
Last analyzed 15 Jun 2026 11:24 UTC
Last updated 16 Jun 2026 15:17 UTC

Labeling

Label good
Label source forager
Traits version 061e3