lock-deadline-guard@1.1.3
Malicious code in lock-deadline-guard (npm)
Analysis
lock-deadline-guard is a mutex wrapper whose sole dependency, mutex-forge, contains an obfuscated implant (lib/withLoad.min.js). On load it fingerprints the host (hostname, platform, CPU count, total memory, uptime, architecture) and exfiltrates the data to Telegram via api[.]telegram[.]org/bot<token>/sendMessage and to Slack via slack[.]com/api/chat.postMessage using a hardcoded xoxb- bot token. It also embeds hardcoded Alchemy and Infura Ethereum RPC endpoints, AES-GCM/PBKDF2/x25519 cryptography, and wallet/private-key handling, and can terminate processes (taskkill/kill). Installing the package pulls in and executes this malicious dependency.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:28 AM
- analyzed
- Aug 13, 2026, 09:29 AM
Related advisories
- async-critical-section@1.0.0
- @biklitime/biklimaster@1.1.6
- dzcvhfruwluwe@1.0.0
- kit-map-vim@1.0.0
- developer-dashboard@1.0.2
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- permit2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.