mdb-vite@1.5.2
Malicious code in mdb-vite (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
mdb-vite@1.5.2 is a combosquat package impersonating the Polymarket CLOB API SDK. When imported, it fetches a remote JavaScript payload from hxxps://svganchordev[.]net/icons/107 (with a custom HTTP header bearrtoken:logo) and executes the response's "credits" field via the Function constructor with full Node.js context (require, process, Buffer, setTimeout). This gives the remote server arbitrary code execution on the installer's machine. The C2 host is svganchordev[.]net, path /icons/107. The package has no install hook — the dropper activates on module import.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 01:29 PM
- analyzed
- Jul 3, 2026, 01:32 PM
Related advisories
- polymarket-apis@1.1.0
- evm-typechain@0.5.4
- polygon-gamma-apis@1.5.2
- polygon-gama-apis@1.4.1
- notifier-utils@1.3.7
- chai-chain-dom@1.3.7
- better-tailwindcss@4.6.3
- transform-es2015-sticky-regex@6.24.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.