LWA-2026-6995 MAL-2026-12339 ↗ confirmed malware

async-mutex-hook@2.1.0

Malicious code in async-mutex-hook (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat of the real async-mutex package. On import, index.js fetches a second-stage payload from 46[.]183[.]25[.]232:45000/icons/108 over HTTPS and executes it via new Function() with full Node.js API access (require, process, Buffer, module, exports), giving the remote server arbitrary code execution on the victim's machine. The package has no repository and its declared purpose (mutex) does not match its behaviour.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 09:03 PM
analyzed
Jul 21, 2026, 09:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.