async-mutex-hook@2.1.0
Malicious code in async-mutex-hook (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat of the real async-mutex package. On import, index.js fetches a second-stage payload from 46[.]183[.]25[.]232:45000/icons/108 over HTTPS and executes it via new Function() with full Node.js API access (require, process, Buffer, module, exports), giving the remote server arbitrary code execution on the victim's machine. The package has no repository and its declared purpose (mutex) does not match its behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 09:03 PM
- analyzed
- Jul 21, 2026, 09:04 PM
Related advisories
- chai-foundry@7.0.3
- rollup-plugin-polyfill-helper@1.0.1
- 1239i32049i@0.1.0
- faust-cont@1.0.0
- quickbuf@1.0.1
- consumerweb-calurls@99.9.1
- consumerweb-creditcollection@99.9.1
- cxpw-offers@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.