LWA-2026-7025 MAL-2026-13381 ↗ confirmed malware

poly-provider-api@4.6.1

Malicious code in poly-provider-api (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

poly-provider-api@4.6.1 is a trojanized package that acts as a remote code execution dropper. When the package is imported (require'd), it fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/108 and executes it via the Function constructor with full Node.js context (require, process, Buffer, setTimeout, etc.), giving the remote payload full access to the host system. The package has no repository and its README describes a non-existent API management library that does not match the actual code.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 03:17 PM
analyzed
Jul 22, 2026, 03:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.