LWA-2026-11036 confirmed malware

prediction-trader@2.3.0

Malicious code in prediction-trader (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

prediction-trader@2.3.0 is a remote-code-execution dropper. Its main entry point index.js fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/108 and executes the returned JSON body (field "credits") via the Function constructor with a full Node.js context (require, process, Buffer, module, setTimeout), giving the remote server arbitrary code execution on the installer's machine. The package's stated purpose (trading utilities) is unrelated to this behaviour.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 10:56 AM
analyzed
Aug 12, 2026, 10:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.