velora-kit@12.0.2
Malicious code in velora-kit (npm)
Analysis
velora-kit@12.0.2 is a remote-code-execution dropper disguised as a utility toolkit. Its index.js exports getPlugin(), which fetches a payload from the C2 server 31[.]97[.]137[.]157:45000 (path /icons/116, HTTP header bearrtoken:logo) and executes the response's data.credits field via the Function constructor with full Node.js context (require, process, Buffer, module, globalThis, timers), giving the remote server arbitrary code execution on the installer's machine. The package also declares dependencies consistent with an implant: node-machine-id (host fingerprinting), socket[.]io-client (command channel), and sqlite3/better-sqlite3 (local database access). A decoy setDefaultModule() function fetches font-awesome icons from cdnjs to mask the real behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 12:55 AM
- analyzed
- Aug 12, 2026, 12:56 AM
Related advisories
- dakumangalsingh@1.0.0
- @dgn-src-click-to-pay-org/srcdcfreleasecert@999.0.1
- developer-dashboard@1.0.2
- passkeys-react@1.0.1
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- ghazaly@99.9.0
- permit2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.