LWA-2026-6685 MAL-2026-10453 ↗ confirmed malware

router-processor@1.5.2

Malicious code in router-processor (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

router-processor@1.5.2 is a remote-code-execution dropper. The package exports a getPlugin() function that fetches code from hxxps://svganchordev[.]net/icons/107 (with custom HTTP header bearrtoken:logo) and executes the response body via new Function() with full Node.js runtime access (require, process, Buffer, console, setTimeout). The README is copied verbatim from the unrelated polymarket-clob-api package. The C2 host is svganchordev[.]net.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 12:05 PM
analyzed
Jul 13, 2026, 12:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.