LWA-2026-11161 confirmed malware

keyed-mutex-map@2.1.2

Malicious code in keyed-mutex-map (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

keyed-mutex-map is a thin wrapper whose only substantive code requires the mutex-forge dependency. On install/require, mutex-forge's obfuscated payload (lib/withLoad.min.js, string-array + custom decoder) fingerprints the host (hostname, platform, arch, CPU count, total memory, uptime) and exfiltrates a "System Report" plus wallet/private-key material to api[.]telegram[.]org /bot<token>/sendMessage and slack[.]com/api/chat.postMessage. It embeds Alchemy (eth-sepolia[.]g[.]alchemy[.]com/v2/...) and Infura (sepolia[.]infura[.]io/v3/...) RPC endpoints and uses AES-GCM/PBKDF2 for encrypted command handling. Installing this package transitively runs the implant.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:28 AM
analyzed
Aug 13, 2026, 09:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.