copytrade-core@2.3.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC
OSV ID
MAL-2026-13944
Ecosystem
npm
Summary
index.js exports a getPlugin function that issues an HTTPS request to the hardcoded bare-IP endpoint https://31.97.137.157:45000/icons/108, takes the response's credits field, passes it to new Function('require','module',...,data.credits), and invokes it with require, module, process, and Buffer injected. This yields arbitrary remote code execution on the consumer's machine, with the fetched payload chosen by whoever controls 31.97.137.157. A separate setDefaultModule function assembles a plausible cdnjs/font-awesome URL from a lookup of legitimate CDN domains (cloudflare.com, fastly.net, etc.) but is never invoked; the exported path uses the bare-IP host instead. Declared dependencies include @primno/dpapi (Windows DPAPI decryption), node-machine-id, and better-sqlite3, matching the toolchain of a browser/wallet credential stealer delivered through this loader.
Source: amazon-inspector (00c8773c5727069f87e54d58cd3679252a90ec0fe3de3a1b4adcb9a3bbff68bd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.