LWA-2026-11167 confirmed malware

try-lock-runner@3.2.1

Malicious code in try-lock-runner (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 Channel

Analysis

try-lock-runner is a thin wrapper that requires the mutex-forge dependency at module load. mutex-forge ships an obfuscated payload (lib/withLoad.min.js) that fingerprints the host (hostname, CPU count, total memory, platform, uptime), reads Ethereum wallet/private-key material, and exfiltrates via Telegram (api[.]telegram[.]org /bot<token>/sendMessage) and Slack (slack[.]com /api/chat.postMessage with a hardcoded xoxb- bot token), using AES-GCM/PBKDF2/x25519 encryption and Alchemy/Infura Sepolia RPC endpoints (eth-sepolia[.]g[.]alchemy[.]com, sepolia[.]infura[.]io). Installing try-lock-runner executes this payload.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:32 AM
analyzed
Aug 13, 2026, 09:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.