VDB
EN

MAL-2026-13962

Malicious code in ventra-kit (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3f023d55f53d30a92c8f06ca661862ee99d338f6d3719247c9390b3169009702) The package's default export (module.exports = () => getPlugin()) issues an HTTPS request to a hardcoded bare-IP host at 31.97.137.157:45000/icons/116 and passes the response's `credits` field into `new Function('require','module','exports',...,'Promise', data.credits)`, executing attacker-controlled JavaScript with full Node.js capabilities (require, process, Buffer, globals). The destination URL is assembled from split protocol/separator/domain/path constants, and an unused `iconDomain` map (cloudflare/fastly/akamai) plus a `setDefaultModule` helper referencing cdnjs/font-awesome provide cover-story framing that disguises the loader as an icon CDN helper. Declared dependencies (@primno/dpapi, better-sqlite3, node-machine-id) are consistent with a Windows browser-credential stealer to be delivered as the remote payload. Any consumer that requires ventra-kit and invokes the default export receives remote code execution on the installer's machine.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / ventra-kit

No fixed version published yet for ventra-kit (npm). Pin to a known-safe version or switch to an alternative.

참고