async-critical-section@1.0.0
Malicious code in async-critical-section (npm)
Analysis
async-critical-section@1.0.0 is a thin wrapper whose only dependency is mutex-forge, which ships an obfuscated implant in lib/withLoad.min.js. On execution the implant fingerprints the host (hostname, platform, arch, CPU count, total/free memory, uptime) and POSTs a system report to Telegram (api[.]telegram[.]org /bot<token>/sendMessage) and Slack (slack[.]com /api/chat.postMessage) using hardcoded bot tokens. It also generates x25519 keypairs, performs AES-GCM/PBKDF2 decryption, reads package.json, spawns detached child processes, kills processes (taskkill / process.kill), and interacts with a Sepolia smart contract (getCwPrivatePublic, getTData1/2) to handle wallet/private keys.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:27 AM
- analyzed
- Aug 13, 2026, 09:27 AM
Related advisories
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- base65-33x@5.0.2
- developer-dashboard@1.0.2
- passport811@1.0.0
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- sme-rko-finance-front-operations-pegasus@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.