LWA-2026-7024 MAL-2026-12513 ↗ confirmed malware

async-mutex-lock@5.3.1

Malicious code in async-mutex-lock (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

async-mutex-lock@5.3.1 is a trojanized package that impersonates a mutex utility but functions as a remote code execution dropper. The main entry point (index.js) fetches a payload from 31[.]97[.]137[.]157:45000 over HTTPS with a custom HTTP header (bearrtoken: logo) and executes the response body via the Function constructor with the full Node.js runtime context (require, process, Buffer, console, timers) passed as parameters, giving the remote server arbitrary code execution on the installer's machine. The package has no repository and its code does not implement any mutex functionality.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 03:15 PM
analyzed
Jul 22, 2026, 03:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.