svgcraft-core@1.0.1
Malicious code in svgcraft-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
svgcraft-core@1.0.1 is a trojanized SVG utility library. The module exports a function getPlugin() that fetches JSON from shorturl.at/nkw3a and passes the "model" field of the response to eval(), enabling remote code execution from an attacker-controlled endpoint. The C2 host is shorturl.at (a URL shortener, allowing the attacker to rotate the real destination without republishing the package).
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 07:24 PM
- analyzed
- Jul 1, 2026, 08:20 PM
Related advisories
- notify-theme@1.3.5
- chain-chai-async@1.3.5
- notifier-log@1.3.5
- eslint-plus@6.0.4
- react-jsonwebtoken@9.0.3
- chai-as-staged@6.0.4
- buffer-util-internal@1.0.13
- cursed-modules@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.