ventrix-kit@1.5.2
Malicious code in ventrix-kit (npm)
Analysis
ventrix-kit@1.5.2 is a trojanized utility library that functions as a remote code execution downloader. On require(), it fetches arbitrary JavaScript from a hardcoded C2 server at 31[.]97[.]137[.]157:45000/icons/116 (with custom header bearrtoken:logo) and executes the response via the Function constructor with full Node.js access (require, process, Buffer). The package ships dependencies for credential theft: @primno/dpapi (Windows DPAPI credential decryption), node-machine-id (machine fingerprinting), better-sqlite3/sqlite3 (browser database access), and socket[.]io-client (C2 channel). The README falsely advertises "zero dependencies" and a benign utility purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 09:15 AM
- analyzed
- Jul 22, 2026, 09:17 AM
Related advisories
- vectormark@1.0.0
- chai-as-stringify@7.0.2
- chai-as-format@2.3.5
- tailwindcss-form-components@1.5.0
- chai-as-deployer@2.3.6
- chai-foundry@7.0.3
- faust-cont@1.0.0
- quickbuf@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.