Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

svgcraft-corenpm

svgcraft-core is a confirmed malicious npm package (MAL-2026-6715) that typosquats a legitimate package to trick installs (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in svgcraft-core (npm)

MAL-2026-6715
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall svgcraft-core

What this malware does

src/index.cjs exports getPlugin(), which returns a function that performs an HTTPS GET to a hardcoded URL 'https://api.avax-test.dev/ext/bc/C/rpc' with TLS verification disabled (rejectUnauthorized: false) and passes the response body to new Function('require', data)(require). Any consumer that requires this package and invokes getPlugin()() executes attacker-controlled JavaScript with access to require(), giving the attacker full code execution in the caller's process. The destination host 'api.avax-test.dev' typosquats Avalanche Fuji's official RPC endpoint 'api.avax-test.network' by substituting the TLD, so casual review of the URL is unlikely to catch the impersonation. The paired ESM entry src/index.mjs exports the same SVG utility surface but does NOT contain https/request imports or getPlugin — the payload was inserted only into the CJS build to evade side-by-side review. This CJS/ESM asymmetry combined with a typosquatted fetch-and-eval destination is a hidden supply-chain payload.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

8 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7

Indicators of compromise (SHA-256)

1407a3b83a7eff7ec054312944ce4bf2c39fc1a26d9c16cda9f7c3c4afa72187
3d44028203c0771b7e6d77ac8addb4d100be6e75992c7ef0bd066035aba86d31
5207167735bdb696743300e61746560ce445beb11da6005ebf7710b7be3408f2
a18879a0b6e0246f4c05a677423bbb9a6aaf8c533467937236288c41e42ef011
3863ea8f67c7365031b5ffb43aaa2721062669b49be8157e1dd32ce19dce511f
d069c2f61ea7089b28abc653c67ba52a79bebde682f7bd83c61b42c2604b961f
b57d1774f2c9a52e324bf1355dd06a37e46282e6dbdd7aa6b83a353472f85d1d
b7a480a72710d21c65c5ebb7872cf57a63870ccb0cd7d3495fec2d3be4837180
5104cdf9acf2ad52208bab27c8679ceb2b2fcb63cd7c7a6438041ed26ee1bf60

Detection & response playbook

Typosquat
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for svgcraft-core (8 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging svgcraft-core across your stack and pipelines.

  2. If you installed it — respond

    svgcraft-core is a typosquat — you almost certainly intended a legitimately-named package. Remove svgcraft-core, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If svgcraft-core was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks svgcraft-core before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. svgcraft-core on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007900IN-MAL-2026-007904IN-MAL-2026-007901IN-MAL-2026-007903IN-MAL-2026-009746IN-MAL-2026-009745GHSA-j9vc-q728-qcx4IN-MAL-2026-011195IN-MAL-2026-013228

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks svgcraft-core-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

svgcraft-core (npm) malicious package — MAL-2026-6715 | O3 Security