LWA-2026-11025 confirmed malware

external-process-live-log@13.5.2

Malicious code in external-process-live-log (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package's main module exports a function that, when called, fetches a payload from hxxp://31[.]97[.]137[.]157:45000/icons/107 (with header bearrtoken: logo) and executes the response body's "credits" field as JavaScript via the Function constructor, with require, process, Buffer, and timers injected into the execution context. This gives the remote server full code execution inside the importing process, including filesystem, network, and child-process access. The package's stated purpose (a Polymarket SDK / process-logging helper) does not match this behaviour.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 02:10 AM
analyzed
Aug 12, 2026, 02:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.