LWA-2026-11166 confirmed malware

single-flight-lock@1.0.0

Malicious code in single-flight-lock (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In Files

Analysis

single-flight-lock@1.0.0 is a wrapper package whose sole dependency is mutex-forge, which ships a 584KB obfuscated file (lib/withLoad.min.d.js) built with the javascript-obfuscator array-shuffle decoder and bundling the ethers.js library (ethers/5.7.2, keccak256, mnemonicToSeed, ciphertext handling) — the standard toolkit for draining cryptocurrency wallets. Installing single-flight-lock pulls this wallet-drainer dependency into the project. The wrapper itself contains no executable payload; it exists to distribute the malicious mutex-forge dependency.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:31 AM
analyzed
Aug 13, 2026, 09:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.