route-processor@3.1.5
Malicious code in route-processor (npm)
Analysis
route-processor@3.1.5 is a trojanized package that claims to be a React SVG helper but contains a remote code execution payload. When imported, the getPlugin function fetches a payload from hxxps://svganchordev[.]net/icons/107 (with custom header bearrtoken: "logo") and executes the response via new Function() with full access to Node.js built-ins (require, process, Buffer, child_process, etc.), enabling arbitrary code execution on the host. The package has no repository and its dependencies (axios, better-sqlite3, express, socket[.]io-client, sqlite3) are unrelated to its stated purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 06:11 PM
- analyzed
- Jul 13, 2026, 06:11 PM
Related advisories
- font-huge@2.5.3
- polymarket-stake-kelly-math@3.8.2
- polymarket-math-stake-kelly@3.7.2
- gifuct@2.1.2
- @sqlite-group/schema-generator@1.0.2
- gptlite@4.0.8
- datavaultx@1.7.1
- auth-gen-next@1.7.13
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.