LWA-2026-7308 confirmed malware

node-internal-svg-loader@1.0.0

Malicious code in node-internal-svg-loader (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package exports functions that claim to fetch SVG icons from CDN providers, but on load it immediately makes HTTP requests to rest-icon-handler[.]store (paths /icons/103, /icons/389) and executes the response body via eval(JSON.parse(b)). This gives the remote server arbitrary code execution on any system that requires the module. The C2 host is rest-icon-handler[.]store.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 05:24 PM
analyzed
Jul 31, 2026, 05:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.