{"id":"MAL-2026-12494","summary":"Malicious code in ventrix-kit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (82b68f964850d0777c1f3993c52e3b66dc425b02ee82fb33bcd958514f730926)\nventrix-kit@1.5.2 ships a loader that, when the package's default `getPlugin` export is invoked, performs an HTTP request to the hardcoded endpoint http://31.97.137.157:45000/icons/116 and passes the response's `credits` field to the JavaScript `Function` constructor, executing the returned code with `require`, `module`, `exports`, `process`, `Buffer`, and other Node globals in scope. The destination is a bare IP on a non-standard port with no pinning, signing, or integrity verification; the executed content is fully attacker-controlled and mutable server-side. The package's metadata and identifiers frame the loader as a CDN icon fetcher (`iconDomain`, `path = \"/icons/\"`, a `bearrtoken: \"logo\"` header, a `font-awesome`-shaped path, and an unused `setDefaultModule` referencing cdnjs/cloudflare/fastly), and the README advertises the package as a lightweight zero-dependency helper while `dependencies` include axios, express, better-sqlite3, @primno/dpapi, node-machine-id, and socket.io-client — a native-Windows-credential (DPAPI) plus persistent-socket stack inconsistent with an icon helper. Any code path that reaches `getPlugin` grants remote code execution on the consumer's host to the operator of 31.97.137.157.\n","modified":"2026-08-05T13:36:23.839553258Z","published":"2026-08-05T12:53:02Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T13:08:47.319355061Z","modified_time":"2026-08-05T12:53:02Z","sha256":"409198f5545f08b1a2102b5e2f5ec038f4a882d4c1088377f1fa7c4cc8bc37dd","source":"amazon-inspector","versions":["0.5.2"],"id":"IN-MAL-2026-014799"},{"modified_time":"2026-08-05T12:55:18Z","sha256":"82b68f964850d0777c1f3993c52e3b66dc425b02ee82fb33bcd958514f730926","source":"amazon-inspector","versions":["1.5.2"],"id":"IN-MAL-2026-014810","import_time":"2026-08-05T13:08:48.14745834Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ventrix-kit/v/0.5.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ventrix-kit/v/1.5.2"}],"affected":[{"package":{"name":"ventrix-kit","ecosystem":"npm","purl":"pkg:npm/ventrix-kit"},"versions":["0.5.2","1.5.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"7a5abb1a5f719ddd3d6dd70d6d4874363c32fcc21540dc72afe18db78aaf3202","tlsh":"ccc1706546fa21a36a67a0eef30f100271a5e3133759e931f48e42902fca568e5f24e8"}],"package_integrity":[{"filename":"ventrix-kit-0.5.2.tgz","hashes":{"sha1":"3fe8164d50a92c30f1ee65e0c22cb3441465aeaf","sha512_sri":"sha512-fs6DFaW5T/9941lOF1roRxT2bohJofq/1eHh7ZpRaFMY20sHwJVTvxeu5GyCPZWtnZgUhOJe7iPAXZZWtKePHw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ventrix-kit/MAL-2026-12494.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}