LWA-2026-6701 MAL-2026-10450 ↗ confirmed malware

font-hub@1.5.2

Malicious code in font-hub (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1552.001 · Credentials In Files

Analysis

The package index.js fetches JSON from hxxps://svganchordev[.]net/icons/107 and passes the response's 'credits' field to a new Function() constructor with full Node.js context (require, process, Buffer, setTimeout, etc.), enabling arbitrary remote code execution. The fetched payload runs with access to all Node.js APIs. The package also ships dependencies including node-machine-id (host fingerprinting), socket[.]io-client (real-time C2 channel), @primno/dpapi (Windows credential access), and sqlite3/better-sqlite3 (local database access) — tooling for the remotely-delivered payload. The README is a copy-paste from the unrelated polymarket-clob-api package, confirming the package is misrepresented.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 12:52 PM
analyzed
Jul 13, 2026, 12:53 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.