LWA-2026-11004 confirmed malware

node-config-svg-contract@1.0.0

Malicious code in node-config-svg-contract (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

node-config-svg-contract@1.0.0 exports functions (getPlugin, setPlugin, getPluginExten) that fetch remote content from the non-standard host rest-icon-handler[.]store (URLs hxxps://rest-icon-handler[.]store/icons/103 and /icons/389) and execute it via eval(JSON.parse(body)) with automatic retry. Any consumer that calls one of these exported functions downloads and runs arbitrary remote code from the .store host. A separate exported function (setDefaultModule) fetches from legitimate CDN hosts (cdnjs[.]cloudflare[.]com, fastly[.]net, akamai[.]net, cloudfront[.]net) and appears to be a benign facade masking the remote-code loader.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 09:10 PM
analyzed
Aug 11, 2026, 09:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.