resource-lease-pool@1.4.2
Malicious code in resource-lease-pool (npm)
Analysis
resource-lease-pool@1.4.2 is a benign-looking resource-pool wrapper whose sole dependency is mutex-forge@^2.0.2, a heavily obfuscated package that runs a C2/exfil implant when installed. The implant fingerprints the host (hostname, platform, CPU count, total memory, uptime), reads wallet/private keys, and POSTs a "System Report" to Telegram (api[.]telegram[.]org /sendMessage, using a hardcoded Telegram bot token and chat id) and to Slack (slack[.]com /api/chat.postMessage, using a hardcoded Slack bot token). It also connects to Ethereum Sepolia RPC endpoints (eth-sepolia[.]g[.]alchemy[.]com/v2/D2-TbkB2m05WXSnSDOCDI and sepolia[.]infura[.]io/v3/dc7257d09fab42eca2c354c32fec1938) and references wallet 0xE390863Dac96a7118C71227C2b09B50cF602D31, using AES-GCM/PBKDF2 decryption and child_process spawn/execSync. Installing resource-lease-pool transitively installs and executes this payload.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:30 AM
- analyzed
- Aug 13, 2026, 09:31 AM
Related advisories
- semaphore-job-pool@2.2.2
- debug-proxy-chrome-devtools@1.0.2
- keyed-mutex-map@2.1.2
- lock-deadline-guard@1.1.3
- async-critical-section@1.0.0
- @biklitime/biklimaster@1.1.6
- dzcvhfruwluwe@1.0.0
- kit-map-vim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.