LWA-2026-11010 confirmed malware

velora-kit@12.0.2

Malicious code in velora-kit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

velora-kit@12.0.2 is a remote-code-execution dropper disguised as a utility toolkit. Its index.js exports getPlugin(), which fetches a payload from the C2 server 31[.]97[.]137[.]157:45000 (path /icons/116, HTTP header bearrtoken:logo) and executes the response's data.credits field via the Function constructor with full Node.js context (require, process, Buffer, module, globalThis, timers), giving the remote server arbitrary code execution on the installer's machine. The package also declares dependencies consistent with an implant: node-machine-id (host fingerprinting), socket[.]io-client (command channel), and sqlite3/better-sqlite3 (local database access). A decoy setDefaultModule() function fetches font-awesome icons from cdnjs to mask the real behaviour.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 12:55 AM
analyzed
Aug 12, 2026, 12:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.