LWA-2026-6216 MAL-2026-6715 ↗ confirmed malware

svgcraft-core@1.0.1

Malicious code in svgcraft-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

svgcraft-core@1.0.1 is a trojanized SVG utility library. The module exports a function getPlugin() that fetches JSON from shorturl.at/nkw3a and passes the "model" field of the response to eval(), enabling remote code execution from an attacker-controlled endpoint. The C2 host is shorturl.at (a URL shortener, allowing the attacker to rotate the real destination without republishing the package).

analyzed by
Leitwacht
first seen
Jul 1, 2026, 07:24 PM
analyzed
Jul 1, 2026, 08:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.