MAL-2026-13944
Dashboard / Malicious Package / MAL-2026-13944
MAL-2026-13944
Summary: Malicious code in copytrade-core (npm)
Details: Source: amazon-inspector (00c8773c5727069f87e54d58cd3679252a90ec0fe3de3a1b4adcb9a3bbff68bd) index.js exports a getPlugin function that issues an HTTPS request to the hardcoded bare-IP endpoint https://31.97.137.157:45000/icons/108, takes the response's `credits` field, passes it to `new Function('require','module',...,data.credits)`, and invokes it with `require`, `module`, `process`, and `Buffer` injected. This yields arbitrary remote code execution on the consumer's machine, with the fetched payload chosen by whoever controls 31.97.137.157. A separate `setDefaultModule` function assembles a plausible cdnjs/font-awesome URL from a lookup of legitimate CDN domains (cloudflare.com, fastly.net, etc.) but is never invoked; the exported path uses the bare-IP host instead. Declared dependencies include @primno/dpapi (Windows DPAPI decryption), node-machine-id, and better-sqlite3, matching the toolchain of a browser/wallet credential stealer delivered through this loader.
Affected packages
Package
Name: copytrade-core
Purl: pkg:npm/copytrade-core
Affected ranges
Type: N/A
Events:
