node-config-svg-contract@1.0.0
Malicious code in node-config-svg-contract (npm)
Analysis
node-config-svg-contract@1.0.0 exports functions (getPlugin, setPlugin, getPluginExten) that fetch remote content from the non-standard host rest-icon-handler[.]store (URLs hxxps://rest-icon-handler[.]store/icons/103 and /icons/389) and execute it via eval(JSON.parse(body)) with automatic retry. Any consumer that calls one of these exported functions downloads and runs arbitrary remote code from the .store host. A separate exported function (setDefaultModule) fetches from legitimate CDN hosts (cdnjs[.]cloudflare[.]com, fastly[.]net, akamai[.]net, cloudfront[.]net) and appears to be a benign facade masking the remote-code loader.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 09:10 PM
- analyzed
- Aug 11, 2026, 09:10 PM
Related advisories
- dakumangalsingh@1.0.0
- internallib_v164@1.0.7
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
- neverthrow-core@1.1.2
- kit-vim-map@1.0.0
- @sqlite-labs-free/createsql@1.0.5
- freeai-proxy@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.