Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @leonardo0902/vortex-kit (npm)

@leonardo0902/vortex-kit version 12.0.2 on npm contains malicious code that fetches and executes arbitrary JavaScript from a hardcoded IP endpoint (31.97.137.157:45000) with full Node.js context access, including require and process capabilities.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any Node.js application that installed @leonardo0902/vortex-kit@12.0.2
Ecosystems
Attack vectors
Affected entities
  • @leonardo0902/vortex-kit · 12.0.2

The npm package @leonardo0902/vortex-kit@12.0.2 contains malicious code that executes remote code whenever the module is loaded or its exported function is invoked. The package makes an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/116 and passes the returned credits field to new Function(), executing attacker-controlled JavaScript with full Node.js context access (require, process, Buffer).\n\nThe malicious fetch is obfuscated by defining a decoy setDefaultModule function that references legitimate CDNs (Cloudflare, Fastly, Akamai, CloudFront) and font-awesome paths, then reuses identical variable names around the actual bare-IP fetch-and-eval to frame it as a static asset download.\n\nThe package bundles native dependencies (@primno/dpapi, better-sqlite3, node-machine-id) consistent with a browser-credential-stealer payload. The remote code is unpinned, unverified, and entirely controlled by the operator of the IP address.\n\nThe incident was identified by Amazon Inspector and credited to the OpenSSF malicious-packages repository.

Indicators of compromise

Packages
  • @leonardo0902/vortex-kit
IPs
  • 31.97.137.157

Remediation

  • Immediately uninstall @leonardo0902/vortex-kit from all projects
  • Audit all Node.js applications that may have installed this package for signs of compromise
  • Rotate any credentials or secrets that may have been exposed on affected systems
  • Review process execution logs and network connections from systems that loaded this package
  • Update dependency lock files to remove this package and verify no other malicious versions are present
  • Monitor for any suspicious outbound connections to 31.97.137.157:45000 in network logs

Sources

  1. GitHub Advisory GHSA-ggj6-v47w-25jr · GitHub Advisory Database

Cite this entry

"Malicious code in @leonardo0902/vortex-kit (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-leonardo0902-vortex-kit-npm-174q9k

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  2. resolvedcritical

    Malicious code in epic-common-node (npm)

    The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.

    npmCompromised package
  3. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  4. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit