LWA-2026-6296 MAL-2026-10144 ↗ confirmed malware

mdb-vite@1.5.2

Malicious code in mdb-vite (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

mdb-vite@1.5.2 is a combosquat package impersonating the Polymarket CLOB API SDK. When imported, it fetches a remote JavaScript payload from hxxps://svganchordev[.]net/icons/107 (with a custom HTTP header bearrtoken:logo) and executes the response's "credits" field via the Function constructor with full Node.js context (require, process, Buffer, setTimeout). This gives the remote server arbitrary code execution on the installer's machine. The C2 host is svganchordev[.]net, path /icons/107. The package has no install hook — the dropper activates on module import.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 01:29 PM
analyzed
Jul 3, 2026, 01:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.