vexium-kit@2.0.2
Malicious code in vexium-kit (npm)
Analysis
vexium-kit@2.0.2 executes remote code at require-time. The package's main entry (index.js) exports a function that, when the module is required, fetches hxxps://31[.]97[.]137[.]157:45000/icons/116 and executes the returned JSON's "credits" field via the Function constructor with a full Node.js context (require, process, Buffer, module, timers). This gives the remote server arbitrary code execution inside the installer's environment. The package is presented as a lightweight utility toolkit but ships heavy unrelated dependencies (better-sqlite3, sqlite3, express, socket[.]io-client, axios, request). C2: 31[.]97[.]137[.]157:45000, path /icons/116.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 12:10 AM
- analyzed
- Aug 11, 2026, 12:11 AM
Related advisories
- dayjs-advanced@1.2.0
- postcss-initial-provider@3.0.4
- godot-kit@1.0.1786316795
- fsbrowse@0.2.28
- cryptostock@1.0.0
- envpack-conf@1.0.1
- iconova-react@1.30.1
- kit-map-streak@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.