MAL-2026-13944
Malicious code in copytrade-core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (00c8773c5727069f87e54d58cd3679252a90ec0fe3de3a1b4adcb9a3bbff68bd) index.js exports a getPlugin function that issues an HTTPS request to the hardcoded bare-IP endpoint https://31.97.137.157:45000/icons/108, takes the response's `credits` field, passes it to `new Function('require','module',...,data.credits)`, and invokes it with `require`, `module`, `process`, and `Buffer` injected. This yields arbitrary remote code execution on the consumer's machine, with the fetched payload chosen by whoever controls 31.97.137.157. A separate `setDefaultModule` function assembles a plausible cdnjs/font-awesome URL from a lookup of legitimate CDN domains (cloudflare.com, fastly.net, etc.) but is never invoked; the exported path uses the bare-IP host instead. Declared dependencies include @primno/dpapi (Windows DPAPI decryption), node-machine-id, and better-sqlite3, matching the toolchain of a browser/wallet credential stealer delivered through this loader.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for copytrade-core (npm). Pin to a known-safe version or switch to an alternative.