LWA-2026-4628 confirmed malware

polygon-bitquery-apis@2.2.3

Malicious code in polygon-bitquery-apis (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In Files

Analysis

A remote-code-execution implant masquerading as a Polygon/Bitquery API helper. The index.js function getPlugin() fetches JSON from hxxps://bet.slotgambit[.]com/icons/107 and passes the response's data.credits field into a new Function() constructor with a full Node.js context (require, process, global, Buffer, setTimeout, console), so the C2 server can return arbitrary JavaScript that runs in the installer's process with full filesystem, env, and module access. A companion setDefaultModule function that constructs CDN URLs serves as a decoy.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 10:14 AM
analyzed
Jun 12, 2026, 10:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.