async-mutex-v2@2.1.0
Malicious code in async-mutex-v2 (npm)
Analysis
async-mutex-v2 is a combosquat of the legitimate async-mutex package. The package ships no mutex implementation — index.js fetches a remote payload from hxxps://svganchordev[.]net/icons/108 and executes it via new Function() with full Node.js context (require, process, Buffer, console, setTimeout) injected as parameters, enabling arbitrary remote code execution on the installer's machine. The package also depends on @primno/dpapi (Windows credential decryption), node-machine-id (device fingerprinting), sqlite3/better-sqlite3, socket[.]io-client, express, and axios — none of which are relevant to a mutex library. The README is a generic template with no actual mutex code.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 11:27 AM
- analyzed
- Jul 14, 2026, 11:27 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.