LWA-2026-7019 MAL-2026-12494 ↗ confirmed malware

ventrix-kit@1.5.2

Malicious code in ventrix-kit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

ventrix-kit@1.5.2 is a trojanized utility library that functions as a remote code execution downloader. On require(), it fetches arbitrary JavaScript from a hardcoded C2 server at 31[.]97[.]137[.]157:45000/icons/116 (with custom header bearrtoken:logo) and executes the response via the Function constructor with full Node.js access (require, process, Buffer). The package ships dependencies for credential theft: @primno/dpapi (Windows DPAPI credential decryption), node-machine-id (machine fingerprinting), better-sqlite3/sqlite3 (browser database access), and socket[.]io-client (C2 channel). The README falsely advertises "zero dependencies" and a benign utility purpose.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 09:15 AM
analyzed
Jul 22, 2026, 09:17 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.