LWA-2026-11164 confirmed malware

priority-mutex-lane@2.5.1

Malicious code in priority-mutex-lane (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

priority-mutex-lane is a thin wrapper package whose only substantive code requires the dependency mutex-forge. Installing it pulls in mutex-forge, a heavily obfuscated module that fingerprints the host (hostname, platform, CPU count, total memory, uptime), reads private keys, and exfiltrates a "System Report" to Telegram (api[.]telegram[.]org /sendMessage) and Slack (slack[.]com /api/chat.postMessage) using hardcoded bot tokens, while also interacting with Ethereum Sepolia RPC endpoints (infura[.]io, alchemy[.]com). The wrapper serves as a delivery vehicle for this malicious dependency.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:29 AM
analyzed
Aug 13, 2026, 09:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.