Intel

AIKIDO-2025-10014

vant is vulnerable to Malicious Code

Malicious Code Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

100

Critical Risk

This Affects:

JSvant
2.13.3 - 2.13.5
Fixed in 2.13.6
3.6.13 - 3.6.15
Fixed in 3.6.16
4.9.11 - 4.9.14
Fixed in 4.9.15

TL;DR

Affected versions of this package are vulnerable to embedded malicious code that executes during the postinstall script. The obfuscated malicious code, located in lib/util/support.js, activates a Monero cryptocurrency miner without user consent. This issue is resolved in versions 2.13.6, 3.6.16, and 4.9.15, where the malicious code has been removed. Users are strongly advised to upgrade to a secure version to mitigate this risk.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vant is vulnerable to Malicious Code in versions 2.13.3 - 2.13.5, 3.6.13 - 3.6.15 and 4.9.11 - 4.9.14.

How to fix this

Upgrade the vant library to the patch version.