LWA-2026-11163 confirmed malware

resource-lease-pool@1.4.2

Malicious code in resource-lease-pool (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

resource-lease-pool@1.4.2 is a benign-looking resource-pool wrapper whose sole dependency is mutex-forge@^2.0.2, a heavily obfuscated package that runs a C2/exfil implant when installed. The implant fingerprints the host (hostname, platform, CPU count, total memory, uptime), reads wallet/private keys, and POSTs a "System Report" to Telegram (api[.]telegram[.]org /sendMessage, using a hardcoded Telegram bot token and chat id) and to Slack (slack[.]com /api/chat.postMessage, using a hardcoded Slack bot token). It also connects to Ethereum Sepolia RPC endpoints (eth-sepolia[.]g[.]alchemy[.]com/v2/D2-TbkB2m05WXSnSDOCDI and sepolia[.]infura[.]io/v3/dc7257d09fab42eca2c354c32fec1938) and references wallet 0xE390863Dac96a7118C71227C2b09B50cF602D31, using AES-GCM/PBKDF2 decryption and child_process spawn/execSync. Installing resource-lease-pool transitively installs and executes this payload.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:30 AM
analyzed
Aug 13, 2026, 09:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.