priority-mutex-lane@2.5.1
Malicious code in priority-mutex-lane (npm)
Analysis
priority-mutex-lane is a thin wrapper package whose only substantive code requires the dependency mutex-forge. Installing it pulls in mutex-forge, a heavily obfuscated module that fingerprints the host (hostname, platform, CPU count, total memory, uptime), reads private keys, and exfiltrates a "System Report" to Telegram (api[.]telegram[.]org /sendMessage) and Slack (slack[.]com /api/chat.postMessage) using hardcoded bot tokens, while also interacting with Ethereum Sepolia RPC endpoints (infura[.]io, alchemy[.]com). The wrapper serves as a delivery vehicle for this malicious dependency.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:29 AM
- analyzed
- Aug 13, 2026, 09:31 AM
Related advisories
- resource-lease-pool@1.4.2
- semaphore-job-pool@2.2.2
- debug-proxy-chrome-devtools@1.0.2
- keyed-mutex-map@2.1.2
- lock-deadline-guard@1.1.3
- async-critical-section@1.0.0
- @biklitime/biklimaster@1.1.6
- dzcvhfruwluwe@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.