LWA-2026-10936 confirmed malware
ventra-kit@1.0.2
Malicious code in ventra-kit (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
ventra-kit@1.0.2 is a remote-code-execution dropper. Its main entry point (index.js) fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/116 and executes the returned JSON's "credits" field via the Function constructor with full Node.js privileges (require, process, Buffer, console). Merely importing the package triggers the fetch-and-execute. The package is described as a utility toolkit but contains no utility code — the entire file is the dropper. C2: 31[.]97[.]137[.]157:45000, path /icons/116.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 06:10 PM
- analyzed
- Aug 10, 2026, 06:11 PM
Related advisories
- @sqlite-labs/createsql@1.0.1
- chai-as-reformed@1.2.0
- dayjs-advanced@1.2.0
- commonjs-assertion@1.2.7
- polymarket-stake-mathss@3.5.2
- runtimekit@1.1.0
- hex-encode-utils@1.0.5
- @noobaihome/amis-uni-area-widget@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.