LWA-2026-10946 confirmed malware

vexium-kit@2.0.2

Malicious code in vexium-kit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

vexium-kit@2.0.2 executes remote code at require-time. The package's main entry (index.js) exports a function that, when the module is required, fetches hxxps://31[.]97[.]137[.]157:45000/icons/116 and executes the returned JSON's "credits" field via the Function constructor with a full Node.js context (require, process, Buffer, module, timers). This gives the remote server arbitrary code execution inside the installer's environment. The package is presented as a lightweight utility toolkit but ships heavy unrelated dependencies (better-sqlite3, sqlite3, express, socket[.]io-client, axios, request). C2: 31[.]97[.]137[.]157:45000, path /icons/116.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 12:10 AM
analyzed
Aug 11, 2026, 12:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.