{"id":"MAL-2026-12514","summary":"Malicious code in async-mutex-v3 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (699abe52cb380ae997f200e0615bfce84cd52d11b98a54244ce5b30478fab336)\nPackage name typosquats `async-mutex` but ships unrelated functionality. The default export `getPlugin` in index.js issues an HTTP request to a hardcoded bare IP endpoint (http://46.183.25.232:45000/icons/108) and passes the response's `credits` field into `new Function('require','module',...,'Promise', data.credits)`, executing attacker-controlled JavaScript with Node privileges (access to require, process, Buffer). Cover-story variable names (`IconProvider`, `iconDomain` referencing cloudflare/fastly/akamai/gcore, path `/ajax/libs/font-awesome/...`, header `bearrtoken: 'logo'`) frame the code as an icon CDN helper, while the actually-used path hits the bare IP. Declared dependencies (better-sqlite3, @primno/dpapi, node-machine-id) are consistent with a credential-stealer post-exploitation pipeline. Any consumer that requires this package and invokes the default export executes whatever JavaScript the remote server returns.\n","modified":"2026-08-05T14:35:13.956918855Z","published":"2026-08-05T13:13:00Z","database_specific":{"malicious-packages-origins":[{"versions":["3.1.0"],"id":"IN-MAL-2026-014928","import_time":"2026-08-05T14:19:43.859834756Z","modified_time":"2026-08-05T13:13:00Z","sha256":"699abe52cb380ae997f200e0615bfce84cd52d11b98a54244ce5b30478fab336","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/async-mutex-v3/v/3.1.0"}],"affected":[{"package":{"name":"async-mutex-v3","ecosystem":"npm","purl":"pkg:npm/async-mutex-v3"},"versions":["3.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"async-mutex-v3-3.1.0.tgz","hashes":{"sha1":"f4adff48d931d29fc8bd875bab153d0cf039bbe2","sha512_sri":"sha512-5gHn8hGVKY84Z+ldKvzIGUrxshf6miV5VMmXSZAsH+smtNWJZNKlOpmt9asxDfQ3fMKLIYm5ySf79mhQfcENbQ=="}}],"evidence_files":[{"tlsh":"30c1616546fa31a36a67e4eef30f10027165e313365de971f48e42902fca568e5f24e8","path":"index.js","sha256":"ce2c680ca6b7355d73cbc131465fc6b2f2508f367b57ecb27a3b05e6e247213f"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/async-mutex-v3/MAL-2026-12514.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}