-= Per source details. Do not edit below this line.=-
router-processor@1.5.2 exposes a getPlugin function that assembles the URL https://svganchordev.net/icons/107 from split constants (protocol, separator, domain, path), fetches a JSON response, and passes the credits field to new Function(...) which is then invoked with a context object exposing require, process, Buffer, and other Node.js internals. This executes arbitrary attacker-controlled JavaScript with full Node privileges in the caller's process. The package declares dependencies on DPAPI bindings (Windows credential decryption), better-sqlite3, and node-machine-id, which are consistent with an infostealer loader capable of decrypting browser credential stores. The package's identity is inconsistent: package.json describes a router processor while the README advertises a Polymarket SDK, and neither matches the observed behavior of fetching remote code from an SVG-themed cover-story domain. The URL split-construction and the misleading credits/getPlugin naming are deliberate evasion of casual review.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010263",
"import_time": "2026-07-13T15:30:31.61096972Z",
"modified_time": "2026-07-13T14:22:59Z",
"sha256": "d15d816c739a85908172d716580a6e4cb0655fe7b2fe35293b218db80f9b2625",
"source": "amazon-inspector",
"versions": [
"1.5.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "f03baeca30cfcbb5903b1d93435435be75b45695cae2510970d803a09ba7071d",
"tlsh": "3ac1616546fa31a36a67e4edf30f10027165e3133759e971f48e42902fca568e5f24e8"
}
],
"package_integrity": [
{
"filename": "router-processor-1.5.2.tgz",
"hashes": {
"sha1": "f92fcbadf1ca6adc9ec80ef6a7ab3f70029798f8",
"sha512_sri": "sha512-YadgQj3hsLz1q08sIeybSGkLPtHkhpwjWOol5obIhAPxVjcu3zw3dDN+uNJp6EU6VTMIYeE0dRNrOQ8supiRGQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/router-processor/MAL-2026-10453.json"