Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in velora-kit (npm)

velora-kit@12.0.2 on npm contains malicious code that fetches and executes arbitrary JavaScript from a hardcoded bare-IP endpoint (31.97.137.157:45000), with access to Node.js runtime capabilities including require, module, process, and Buffer. The payload is designed to steal credentials and wallet data from local browser profiles.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any Node.js application that installed velora-kit@12.0.2
Ecosystems
Attack vectors
Affected entities
  • velora-kit · 12.0.2

velora-kit version 12.0.2 published to npm contains a malicious getPlugin() function that fetches content from a hardcoded bare-IP endpoint at https://31.97.137.157:45000/icons/116. The response's data.credits field is passed to new Function(...) and executed with full Node.js privileges, including injected access to require, module, process, Buffer, and Promise.

The attack is obfuscated through variable naming and URL construction patterns designed to resemble a legitimate CDN icon fetcher. The package declares dependencies on @primno/dpapi (Windows DPAPI decryption), better-sqlite3/sqlite3 (browser-profile database access), node-machine-id, socket.io-client, request, and axios—providing the fetched second-stage payload with capabilities for credential and wallet theft from local browser profiles.

This incident was identified and reported by the OpenSSF's malicious-packages project (MAL-2026-13961).

Indicators of compromise

Packages
  • velora-kit@12.0.2
IPs
  • 31.97.137.157

Remediation

  • Immediately uninstall velora-kit@12.0.2 from all affected projects
  • Audit npm install logs to identify all systems that installed this version
  • Rotate all credentials and secrets that may have been accessed by the malicious code
  • Review browser profile data and wallet applications for unauthorized access or theft
  • Update to a patched version of velora-kit if available, or remove the dependency entirely
  • Consider running security scans on affected systems for signs of credential exfiltration

Sources

  1. GitHub Advisory GHSA-xw23-8m9g-4hr8 · GitHub Advisory Database

Cite this entry

"Malicious code in velora-kit (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-velora-kit-npm-17j4w3

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in chlklib

    Malware was discovered in the npm package chlklib, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2. resolvedcritical

    Malware in alphazone

    The npm package alphazone contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  3. containedcritical

    Malware in chai-as-deployer

    Malware was discovered in the npm package chai-as-deployer, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  4. containedcritical

    Malware in checkout-common-tokens

    Malware was discovered in the npm package checkout-common-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package