svg-fetcher@2.4.1
Malicious code in svg-fetcher (npm)
Analysis
svg-fetcher@2.4.1 is a trojanized package that performs remote code execution. The exported getPlugin() function fetches JSON from hxxps://svganchordev[.]net/icons/106 and passes the response body into new Function() with full Node.js built-in access (require, module, exports, process, console, Buffer), enabling the remote server to execute arbitrary JavaScript on the consumer's machine. The package also ships a real OpenSSH ed25519 private key (package/gitlab) and its corresponding public key (package/gitlab.pub). The package has no install hooks — the payload runs when the consumer calls the exported getPlugin() function. C2 host: svganchordev[.]net, path: /icons/106, request header: bearrtoken: logo.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 07:08 PM
- analyzed
- Jul 11, 2026, 07:09 PM
Related advisories
- cookie-sign@2.3.5
- babel-preset-lib-client@4.9.11
- kuaishou@99.9.9
- chai-as-doc@2.3.5
- polymarket-mcp-v2@2.1.6
- nonenull1@1.0.0
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.