LWA-2026-11166 confirmed malware
single-flight-lock@1.0.0
Malicious code in single-flight-lock (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In Files
Analysis
single-flight-lock@1.0.0 is a wrapper package whose sole dependency is mutex-forge, which ships a 584KB obfuscated file (lib/withLoad.min.d.js) built with the javascript-obfuscator array-shuffle decoder and bundling the ethers.js library (ethers/5.7.2, keccak256, mnemonicToSeed, ciphertext handling) — the standard toolkit for draining cryptocurrency wallets. Installing single-flight-lock pulls this wallet-drainer dependency into the project. The wrapper itself contains no executable payload; it exists to distribute the malicious mutex-forge dependency.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:31 AM
- analyzed
- Aug 13, 2026, 09:34 AM
Related advisories
- priority-mutex-lane@2.5.1
- resource-lease-pool@1.4.2
- semaphore-job-pool@2.2.2
- debug-proxy-chrome-devtools@1.0.2
- keyed-mutex-map@2.1.2
- lock-deadline-guard@1.1.3
- async-critical-section@1.0.0
- @biklitime/biklimaster@1.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.