LWA-2026-4628 confirmed malware
polygon-bitquery-apis@2.2.3
Malicious code in polygon-bitquery-apis (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In Files
Analysis
A remote-code-execution implant masquerading as a Polygon/Bitquery API helper. The index.js function getPlugin() fetches JSON from hxxps://bet.slotgambit[.]com/icons/107 and passes the response's data.credits field into a new Function() constructor with a full Node.js context (require, process, global, Buffer, setTimeout, console), so the C2 server can return arbitrary JavaScript that runs in the installer's process with full filesystem, env, and module access. A companion setDefaultModule function that constructs CDN URLs serves as a decoy.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 10:14 AM
- analyzed
- Jun 12, 2026, 10:16 AM
Related advisories
- pocbitbarrontest@1.0.0
- pino-sdk-v2@9.9.0
- pino-pretty-logs@1.1.0
- pino-pretty-logger@1.1.1
- pino-formatter@1.1.12
- period-newline@0.1.0
- pampipes@1.1.9
- coral-wraith@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.