keyed-mutex-map@2.1.2
Malicious code in keyed-mutex-map (npm)
Analysis
keyed-mutex-map is a thin wrapper whose only substantive code requires the mutex-forge dependency. On install/require, mutex-forge's obfuscated payload (lib/withLoad.min.js, string-array + custom decoder) fingerprints the host (hostname, platform, arch, CPU count, total memory, uptime) and exfiltrates a "System Report" plus wallet/private-key material to api[.]telegram[.]org /bot<token>/sendMessage and slack[.]com/api/chat.postMessage. It embeds Alchemy (eth-sepolia[.]g[.]alchemy[.]com/v2/...) and Infura (sepolia[.]infura[.]io/v3/...) RPC endpoints and uses AES-GCM/PBKDF2 for encrypted command handling. Installing this package transitively runs the implant.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:28 AM
- analyzed
- Aug 13, 2026, 09:29 AM
Related advisories
- lock-deadline-guard@1.1.3
- async-critical-section@1.0.0
- @biklitime/biklimaster@1.1.6
- dzcvhfruwluwe@1.0.0
- kit-map-vim@1.0.0
- developer-dashboard@1.0.2
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.