LWA-2026-11529 confirmed malware

express-session-handler@2.3.3

Malicious code in express-session-handler (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

express-session-handler@2.3.3 executes malicious code immediately when required. On load, index.js performs an HTTPS GET to hxxps://api[.]jsonbin[.]io/v3/b/6a4f5816f5f4af5e29762c92 (sending a 'Bearrtoken: logo' header), reads the 'cerookie' field from the returned JSON, and executes it as JavaScript via the Function constructor with full access to Node's require. This gives the remote operator arbitrary code execution inside any process that imports the package. The package name mimics the legitimate express-session middleware.

analyzed by
Leitwacht
first seen
Aug 20, 2026, 03:31 PM
analyzed
Aug 20, 2026, 03:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.