OpenSSF/OSV advisory MAL-2026-13939 confirms this npm version as malicious. The main module in @leonardo0902/vortex-kit@12.0.2 issues an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/116 and passes the returned `credits` field to `new Function('require',..., 'Promise', data.credits)`, executing attacker-controlled JavaScript with full Node context (require, process, Buffer) whenever the module is loaded and its exported function is invoked...
Source passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L6Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L6Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg