LWA-2026-11036 confirmed malware
prediction-trader@2.3.0
Malicious code in prediction-trader (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
prediction-trader@2.3.0 is a remote-code-execution dropper. Its main entry point index.js fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/108 and executes the returned JSON body (field "credits") via the Function constructor with a full Node.js context (require, process, Buffer, module, setTimeout), giving the remote server arbitrary code execution on the installer's machine. The package's stated purpose (trading utilities) is unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 10:56 AM
- analyzed
- Aug 12, 2026, 10:57 AM
Related advisories
- external-process-live-log@13.5.2
- kit-map-vim@1.0.0
- velora-kit@12.0.2
- node-config-svg-contract@1.0.0
- dakumangalsingh@1.0.0
- internallib_v164@1.0.7
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.