LWA-2026-11160 confirmed malware

lock-deadline-guard@1.1.3

Malicious code in lock-deadline-guard (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

lock-deadline-guard is a mutex wrapper whose sole dependency, mutex-forge, contains an obfuscated implant (lib/withLoad.min.js). On load it fingerprints the host (hostname, platform, CPU count, total memory, uptime, architecture) and exfiltrates the data to Telegram via api[.]telegram[.]org/bot<token>/sendMessage and to Slack via slack[.]com/api/chat.postMessage using a hardcoded xoxb- bot token. It also embeds hardcoded Alchemy and Infura Ethereum RPC endpoints, AES-GCM/PBKDF2/x25519 cryptography, and wallet/private-key handling, and can terminate processes (taskkill/kill). Installing the package pulls in and executes this malicious dependency.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:28 AM
analyzed
Aug 13, 2026, 09:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.