MAL-2026-13939

    Dashboard / Malicious Package / MAL-2026-13939

    MAL-2026-13939

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in @leonardo0902/vortex-kit (npm)

    Details: Source: amazon-inspector (1707e031a6c470479ecbd0b01a480cc801a9d049a3732abc265ccad8791272a9) The main module in @leonardo0902/[email protected] issues an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/116 and passes the returned `credits` field to `new Function('require',..., 'Promise', data.credits)`, executing attacker-controlled JavaScript with full Node context (require, process, Buffer) whenever the module is loaded and its exported function is invoked. The fetch destination is disguised as a static-asset endpoint: the file defines a decoy `setDefaultModule` referencing legitimate CDNs (cloudflare, fastly, akamai, cloudfront) and a font-awesome path, then reuses the identical variable names (`protocol`, `domain`, `path`, `head`, `bearrtoken: 'logo'`) around the bare-IP fetch-and-eval to frame it as an icon download. Bundled native dependencies (@primno/dpapi, better-sqlite3, node-machine-id) are consistent with a dynamically delivered browser-credential-stealer payload. The remote code is unpinned, unverified, and controlled entirely by whoever operates the IP.

    Affected packages

    Package

    Name: @leonardo0902/vortex-kit

    Purl: pkg:npm/%40leonardo0902/vortex-kit

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    12.0.2