try-lock-runner@3.2.1
Malicious code in try-lock-runner (npm)
Analysis
try-lock-runner is a thin wrapper that requires the mutex-forge dependency at module load. mutex-forge ships an obfuscated payload (lib/withLoad.min.js) that fingerprints the host (hostname, CPU count, total memory, platform, uptime), reads Ethereum wallet/private-key material, and exfiltrates via Telegram (api[.]telegram[.]org /bot<token>/sendMessage) and Slack (slack[.]com /api/chat.postMessage with a hardcoded xoxb- bot token), using AES-GCM/PBKDF2/x25519 encryption and Alchemy/Infura Sepolia RPC endpoints (eth-sepolia[.]g[.]alchemy[.]com, sepolia[.]infura[.]io). Installing try-lock-runner executes this payload.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:32 AM
- analyzed
- Aug 13, 2026, 09:35 AM
Related advisories
- semaphore-job-pool@2.2.2
- postcss-initialize-plugin@3.0.4
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- neverthrow-core@1.1.2
- kit-vim-map@1.0.0
- vexium-kit@2.0.2
- dayjs-advanced@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.