async-lock-queue@3.0.1
Malicious code in async-lock-queue (npm)
Analysis
async-lock-queue is a thin FIFO-queue wrapper whose sole dependency, mutex-forge, is a heavily-obfuscated implant. On install/require, mutex-forge's lib/withLoad.min.js fingerprints the host (hostname, platform, arch, CPU count, total memory, uptime), reads wallet/private-key files, and exfiltrates the collected data to a Telegram bot (api[.]telegram[.]org /bot<token>/sendMessage) and a Slack bot (slack[.]com /api/chat.postMessage) using embedded bot tokens. It also interacts with Ethereum smart contracts (getSPubKey/setCPubKey/getChunk) using embedded Alchemy and Infura RPC keys (eth-sepolia[.]g[.]alchemy[.]com, sepolia[.]infura[.]io), and encrypts its command channel with AES-GCM/PBKDF2/x25519. Installing async-lock-queue pulls in and executes this payload.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:46 AM
- analyzed
- Aug 13, 2026, 11:46 AM
Related advisories
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- try-lock-runner@3.2.1
- semaphore-job-pool@2.2.2
- postcss-initialize-plugin@3.0.4
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- neverthrow-core@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.