LWA-2026-5307 confirmed malware

tradepilot@2.3.3

Malicious code in tradepilot (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In FilesT1082 · System Information Discovery

Analysis

The package tradepilot@2.3.3 is a remote-code-execution downloader disguised as a trading bot. At runtime (when required/imported), it silently fetches a second-stage payload from hxxps://bet[.]slotgambit[.]com/icons/106 (with header bearrtoken: logo) and executes the response body's "credits" field via new Function(...) with full Node.js access (require, process, Buffer, module.exports). This gives the attacker arbitrary code execution in the victim's environment. The package depends on @primno/dpapi (Windows DPAPI credential decryptor), node-machine-id (host fingerprinting), better-sqlite3/sqlite3 (credential-database access), socket[.]io-client (real-time C2 channel), and axios (HTTP). The C2 host is bet[.]slotgambit[.]com, path /icons/106, protocol HTTPS. The package has no install lifecycle hooks — execution triggers on import.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:33 AM
analyzed
Jun 15, 2026, 05:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.