poly-provider-api@4.6.1
Malicious code in poly-provider-api (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
poly-provider-api@4.6.1 is a trojanized package that acts as a remote code execution dropper. When the package is imported (require'd), it fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/108 and executes it via the Function constructor with full Node.js context (require, process, Buffer, setTimeout, etc.), giving the remote payload full access to the host system. The package has no repository and its README describes a non-existent API management library that does not match the actual code.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 03:17 PM
- analyzed
- Jul 22, 2026, 03:18 PM
Related advisories
- async-mutex-lock@5.3.1
- dbconnectify@1.0.2
- utility-kit-ts@1.3.2
- ts-toolkit-plus@1.3.2
- ventrix-kit@1.5.2
- @copilot-mcp/apex@1.0.0
- vectormark@1.0.0
- vite-config-svg@1.1.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.