godot-kit@1.0.1786316795
Malicious code in godot-kit (npm)
Analysis
godot-kit@1.0.1786316795 ships a hidden remote-code-execution dropper appended to lang/gdscript.js. On load, the payload hardcodes the Ethereum wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a and queries public ETH RPC endpoints for transactions sent FROM that wallet; it decodes the `to` field of a matching transaction as hex to derive two C2 IP addresses. It then fetches XOR-encrypted second-stage payloads (keys q4FZkxX{!h,Sr3=@ and y-p_>d$0B&@^1aQk) from hxxp://<c2-ip>:443/0x/cls and hxxp://<c2-ip>:443/0x/ls, decrypts them, and executes them both via eval and by spawning a detached, hidden `node -e` process. The C2 rendezvous is hidden in Ethereum blockchain transactions, so the C2 IPs are only resolvable at runtime.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 02:25 AM
- analyzed
- Aug 10, 2026, 02:25 AM
- weekly installs
- 67
Related advisories
- fsbrowse@0.2.28
- cryptostock@1.0.0
- envpack-conf@1.0.1
- iconova-react@1.30.1
- kit-map-streak@1.0.0
- @kolbo/mcp@1.57.1
- map-streak-kit@1.0.0
- platform-ui-colors@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.