LWA-2026-10936 confirmed malware

ventra-kit@1.0.2

Malicious code in ventra-kit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

ventra-kit@1.0.2 is a remote-code-execution dropper. Its main entry point (index.js) fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/116 and executes the returned JSON's "credits" field via the Function constructor with full Node.js privileges (require, process, Buffer, console). Merely importing the package triggers the fetch-and-execute. The package is described as a utility toolkit but contains no utility code — the entire file is the dropper. C2: 31[.]97[.]137[.]157:45000, path /icons/116.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 06:10 PM
analyzed
Aug 10, 2026, 06:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.