-= Per source details. Do not edit below this line.=-
ventrix-kit@1.5.2 ships a loader that, when the package's default getPlugin export is invoked, performs an HTTP request to the hardcoded endpoint http://31.97.137.157:45000/icons/116 and passes the response's credits field to the JavaScript Function constructor, executing the returned code with require, module, exports, process, Buffer, and other Node globals in scope. The destination is a bare IP on a non-standard port with no pinning, signing, or integrity verification; the executed content is fully attacker-controlled and mutable server-side. The package's metadata and identifiers frame the loader as a CDN icon fetcher (iconDomain, path = "/icons/", a bearrtoken: "logo" header, a font-awesome-shaped path, and an unused setDefaultModule referencing cdnjs/cloudflare/fastly), and the README advertises the package as a lightweight zero-dependency helper while dependencies include axios, express, better-sqlite3, @primno/dpapi, node-machine-id, and socket.io-client — a native-Windows-credential (DPAPI) plus persistent-socket stack inconsistent with an icon helper. Any code path that reaches getPlugin grants remote code execution on the consumer's host to the operator of 31.97.137.157.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-05T12:53:02Z",
"source": "amazon-inspector",
"sha256": "409198f5545f08b1a2102b5e2f5ec038f4a882d4c1088377f1fa7c4cc8bc37dd",
"import_time": "2026-08-05T13:08:47.319355061Z",
"id": "IN-MAL-2026-014799",
"versions": [
"0.5.2"
]
},
{
"modified_time": "2026-08-05T12:55:18Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-014810",
"import_time": "2026-08-05T13:08:48.14745834Z",
"sha256": "82b68f964850d0777c1f3993c52e3b66dc425b02ee82fb33bcd958514f730926",
"versions": [
"1.5.2"
]
}
]
}{
"package_integrity": [
{
"filename": "ventrix-kit-0.5.2.tgz",
"hashes": {
"sha512_sri": "sha512-fs6DFaW5T/9941lOF1roRxT2bohJofq/1eHh7ZpRaFMY20sHwJVTvxeu5GyCPZWtnZgUhOJe7iPAXZZWtKePHw==",
"sha1": "3fe8164d50a92c30f1ee65e0c22cb3441465aeaf"
}
}
],
"evidence_files": [
{
"tlsh": "ccc1706546fa21a36a67a0eef30f100271a5e3133759e931f48e42902fca568e5f24e8",
"sha256": "7a5abb1a5f719ddd3d6dd70d6d4874363c32fcc21540dc72afe18db78aaf3202",
"path": "index.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ventrix-kit/MAL-2026-12494.json"
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]