external-process-live-log@13.5.2
Malicious code in external-process-live-log (npm)
Analysis
The package's main module exports a function that, when called, fetches a payload from hxxp://31[.]97[.]137[.]157:45000/icons/107 (with header bearrtoken: logo) and executes the response body's "credits" field as JavaScript via the Function constructor, with require, process, Buffer, and timers injected into the execution context. This gives the remote server full code execution inside the importing process, including filesystem, network, and child-process access. The package's stated purpose (a Polymarket SDK / process-logging helper) does not match this behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 02:10 AM
- analyzed
- Aug 12, 2026, 02:11 AM
Related advisories
- kit-map-vim@1.0.0
- velora-kit@12.0.2
- node-config-svg-contract@1.0.0
- dakumangalsingh@1.0.0
- internallib_v164@1.0.7
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
- neverthrow-core@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.