async-mutex-lock@5.3.1
Malicious code in async-mutex-lock (npm)
Analysis
async-mutex-lock@5.3.1 is a trojanized package that impersonates a mutex utility but functions as a remote code execution dropper. The main entry point (index.js) fetches a payload from 31[.]97[.]137[.]157:45000 over HTTPS with a custom HTTP header (bearrtoken: logo) and executes the response body via the Function constructor with the full Node.js runtime context (require, process, Buffer, console, timers) passed as parameters, giving the remote server arbitrary code execution on the installer's machine. The package has no repository and its code does not implement any mutex functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 03:15 PM
- analyzed
- Jul 22, 2026, 03:16 PM
Related advisories
- dbconnectify@1.0.2
- utility-kit-ts@1.3.2
- ts-toolkit-plus@1.3.2
- ventrix-kit@1.5.2
- @copilot-mcp/apex@1.0.0
- vectormark@1.0.0
- vite-config-svg@1.1.7
- crypto-checkout-api@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.