LWA-2026-10901 confirmed malware

godot-kit@1.0.1786316795

Malicious code in godot-kit (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1573 · Encrypted Channel

Analysis

godot-kit@1.0.1786316795 ships a hidden remote-code-execution dropper appended to lang/gdscript.js. On load, the payload hardcodes the Ethereum wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a and queries public ETH RPC endpoints for transactions sent FROM that wallet; it decodes the `to` field of a matching transaction as hex to derive two C2 IP addresses. It then fetches XOR-encrypted second-stage payloads (keys q4FZkxX{!h,Sr3=@ and y-p_>d$0B&@^1aQk) from hxxp://<c2-ip>:443/0x/cls and hxxp://<c2-ip>:443/0x/ls, decrypts them, and executes them both via eval and by spawning a detached, hidden `node -e` process. The C2 rendezvous is hidden in Ethereum blockchain transactions, so the C2 IPs are only resolvable at runtime.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 02:25 AM
analyzed
Aug 10, 2026, 02:25 AM
weekly installs
67

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.