LWA-2026-6629 MAL-2026-10427 ↗ confirmed malware

svg-fetcher@2.4.1

Malicious code in svg-fetcher (npm)

Analysis

svg-fetcher@2.4.1 is a trojanized package that performs remote code execution. The exported getPlugin() function fetches JSON from hxxps://svganchordev[.]net/icons/106 and passes the response body into new Function() with full Node.js built-in access (require, module, exports, process, console, Buffer), enabling the remote server to execute arbitrary JavaScript on the consumer's machine. The package also ships a real OpenSSH ed25519 private key (package/gitlab) and its corresponding public key (package/gitlab.pub). The package has no install hooks — the payload runs when the consumer calls the exported getPlugin() function. C2 host: svganchordev[.]net, path: /icons/106, request header: bearrtoken: logo.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 07:08 PM
analyzed
Jul 11, 2026, 07:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.