LWA-2026-11529 confirmed malware
express-session-handler@2.3.3
Malicious code in express-session-handler (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
express-session-handler@2.3.3 executes malicious code immediately when required. On load, index.js performs an HTTPS GET to hxxps://api[.]jsonbin[.]io/v3/b/6a4f5816f5f4af5e29762c92 (sending a 'Bearrtoken: logo' header), reads the 'cerookie' field from the returned JSON, and executes it as JavaScript via the Function constructor with full access to Node's require. This gives the remote operator arbitrary code execution inside any process that imports the package. The package name mimics the legitimate express-session middleware.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 03:31 PM
- analyzed
- Aug 20, 2026, 03:31 PM
Related advisories
- @httttt/mcp-npx-fetch-1@1.0.0
- @saidddddddddd/ggsgg@1.0.0
- mc-provider@1.0.10
- @oss-core-eng/data-formatter@1.0.1
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- anhn-cli@1.1.4
- @wizloft/harness-validation@0.1.1-alpha.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.