VDB
Sign up
—

MAL-2026-12514

Malicious code in async-mutex-v3 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (699abe52cb380ae997f200e0615bfce84cd52d11b98a54244ce5b30478fab336) Package name typosquats `async-mutex` but ships unrelated functionality. The default export `getPlugin` in index.js issues an HTTP request to a hardcoded bare IP endpoint (http://46.183.25.232:45000/icons/108) and passes the response's `credits` field into `new Function('require','module',...,'Promise', data.credits)`, executing attacker-controlled JavaScript with Node privileges (access to require, process, Buffer). Cover-story variable names (`IconProvider`, `iconDomain` referencing cloudflare/fastly/akamai/gcore, path `/ajax/libs/font-awesome/...`, header `bearrtoken: 'logo'`) frame the code as an icon CDN helper, while the actually-used path hits the bare IP. Declared dependencies (better-sqlite3, @primno/dpapi, node-machine-id) are consistent with a credential-stealer post-exploitation pipeline. Any consumer that requires this package and invokes the default export executes whatever JavaScript the remote server returns.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/async-mutex-v3

No fixed version published yet for async-mutex-v3 (npm). Pin to a known-safe version or switch to an alternative.

References