MAL-2026-12514

    Dashboard / Malicious Package / MAL-2026-12514

    MAL-2026-12514

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in async-mutex-v3 (npm)

    Details: Source: amazon-inspector (699abe52cb380ae997f200e0615bfce84cd52d11b98a54244ce5b30478fab336) Package name typosquats `async-mutex` but ships unrelated functionality. The default export `getPlugin` in index.js issues an HTTP request to a hardcoded bare IP endpoint (http://46.183.25.232:45000/icons/108) and passes the response's `credits` field into `new Function('require','module',...,'Promise', data.credits)`, executing attacker-controlled JavaScript with Node privileges (access to require, process, Buffer). Cover-story variable names (`IconProvider`, `iconDomain` referencing cloudflare/fastly/akamai/gcore, path `/ajax/libs/font-awesome/...`, header `bearrtoken: 'logo'`) frame the code as an icon CDN helper, while the actually-used path hits the bare IP. Declared dependencies (better-sqlite3, @primno/dpapi, node-machine-id) are consistent with a credential-stealer post-exploitation pipeline. Any consumer that requires this package and invokes the default export executes whatever JavaScript the remote server returns.

    Affected packages

    Package

    Name: async-mutex-v3

    Purl: pkg:npm/async-mutex-v3

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.1.0