LWA-2026-7308 confirmed malware
node-internal-svg-loader@1.0.0
Malicious code in node-internal-svg-loader (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The package exports functions that claim to fetch SVG icons from CDN providers, but on load it immediately makes HTTP requests to rest-icon-handler[.]store (paths /icons/103, /icons/389) and executes the response body via eval(JSON.parse(b)). This gives the remote server arbitrary code execution on any system that requires the module. The C2 host is rest-icon-handler[.]store.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 05:24 PM
- analyzed
- Jul 31, 2026, 05:24 PM
Related advisories
- tailwind-opentype@1.2.3
- vite-tsconfig-svg@1.1.4
- rollup-plugin-polyfill-hold@1.0.5
- ts-poly-utls@1.2.4
- postcss-animate-css-vars@2.0.3
- log-min@1.0.13
- streak-metrics-math@1.0.1
- runtime-sentinel@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.