Malicious code in @leonardo0902/vortex-kit (npm)
@leonardo0902/vortex-kit version 12.0.2 on npm contains malicious code that fetches and executes arbitrary JavaScript from a hardcoded IP endpoint (31.97.137.157:45000) with full Node.js context access, including require and process capabilities.
- Disclosed
- Last updated
- Blast radius
- Any Node.js application that installed @leonardo0902/vortex-kit@12.0.2
- Ecosystems
- Attack vectors
- Affected entities
- @leonardo0902/vortex-kit · 12.0.2
The npm package @leonardo0902/vortex-kit@12.0.2 contains malicious code that executes remote code whenever the module is loaded or its exported function is invoked. The package makes an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/116 and passes the returned credits field to new Function(), executing attacker-controlled JavaScript with full Node.js context access (require, process, Buffer).\n\nThe malicious fetch is obfuscated by defining a decoy setDefaultModule function that references legitimate CDNs (Cloudflare, Fastly, Akamai, CloudFront) and font-awesome paths, then reuses identical variable names around the actual bare-IP fetch-and-eval to frame it as a static asset download.\n\nThe package bundles native dependencies (@primno/dpapi, better-sqlite3, node-machine-id) consistent with a browser-credential-stealer payload. The remote code is unpinned, unverified, and entirely controlled by the operator of the IP address.\n\nThe incident was identified by Amazon Inspector and credited to the OpenSSF malicious-packages repository.
Indicators of compromise
- Packages
- @leonardo0902/vortex-kit
- IPs
- 31.97.137.157
Remediation
- Immediately uninstall @leonardo0902/vortex-kit from all projects
- Audit all Node.js applications that may have installed this package for signs of compromise
- Rotate any credentials or secrets that may have been exposed on affected systems
- Review process execution logs and network connections from systems that loaded this package
- Update dependency lock files to remove this package and verify no other malicious versions are present
- Monitor for any suspicious outbound connections to 31.97.137.157:45000 in network logs
Sources
- GitHub Advisory GHSA-ggj6-v47w-25jr · GitHub Advisory Database
Cite this entry
"Malicious code in @leonardo0902/vortex-kit (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-leonardo0902-vortex-kit-npm-174q9k
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in epic-common-node (npm)
The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.
npmCompromised package - containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit