shared-slot-gate@1.1.2
Malicious code in shared-slot-gate (npm)
Analysis
shared-slot-gate is a semaphore wrapper whose only dependency, mutex-forge, is a C2 implant. Installing shared-slot-gate transitively installs mutex-forge, which on execution collects host metadata (hostname, platform, architecture, CPU count, memory, uptime) and exfiltrates it to a Telegram bot (api[.]telegram[.]org/bot<token>/sendMessage, chat -1003952553968) and a Slack workspace (slack[.]com/api/chat.postMessage, channel C0B8XPGcKQS). It generates an X25519 keypair, derives a shared secret, and registers a public key on a Sepolia smart contract at 0xE390863Dac96a7118C71227C2b09B50cF602D31 via Alchemy (eth-sepolia[.]g[.]alchemy[.]com) and Infura (sepolia[.]infura[.]io) RPC endpoints. It spawns detached child processes that poll Slack/Telegram for commands, download AES-GCM-encrypted chunks, decrypt them with PBKDF2-derived keys, and execute the resulting payloads. It also terminates processes and self-deletes to evade analysis.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:31 AM
- analyzed
- Aug 13, 2026, 09:36 AM
Related advisories
- async-critical-section@1.0.0
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- base65-33x@5.0.2
- developer-dashboard@1.0.2
- passport811@1.0.0
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.