tradepilot@2.3.3
Malicious code in tradepilot (npm)
Analysis
The package tradepilot@2.3.3 is a remote-code-execution downloader disguised as a trading bot. At runtime (when required/imported), it silently fetches a second-stage payload from hxxps://bet[.]slotgambit[.]com/icons/106 (with header bearrtoken: logo) and executes the response body's "credits" field via new Function(...) with full Node.js access (require, process, Buffer, module.exports). This gives the attacker arbitrary code execution in the victim's environment. The package depends on @primno/dpapi (Windows DPAPI credential decryptor), node-machine-id (host fingerprinting), better-sqlite3/sqlite3 (credential-database access), socket[.]io-client (real-time C2 channel), and axios (HTTP). The C2 host is bet[.]slotgambit[.]com, path /icons/106, protocol HTTPS. The package has no install lifecycle hooks — execution triggers on import.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:33 AM
- analyzed
- Jun 15, 2026, 05:35 AM
Related advisories
- totally-safe-util@1.0.1
- tiny-string-parser@0.1.2
- hemi-supply-cron@999.0.0
- ve-hemi-rewards@999.0.0
- token-prices-cron@999.0.0
- hemi-earn-actions@999.0.0
- portal-backend@999.0.0
- thepackagethatworks_@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.