LWA-2026-11721 confirmed malware
express-helmet@0.0.1
Malicious code in express-helmet (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
express-helmet@0.0.1 is a combosquat of the popular helmet package: it uses the name express-helmet and mirrors helmet's description, repository, and homepage while shipping a verbatim copy of helmet's source (CSP and HTTP-header middleware in index.cjs/index.mjs). The package is published under a name designed to impersonate the legitimate helmet package, which can lead installers to pull it in place of the real one. The current version's code is a clean copy with no lifecycle hooks, no network activity, and no credential access.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 11:00 AM
- analyzed
- Aug 29, 2026, 11:00 AM
Related advisories
- dsh-tauri-rightclick@0.4.9
- nx-app@9999.0.0-security-test
- @berrysdk/transport@0.1.9
- @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be
- cacao1@9.9.9
- melbet-ivoire@1.0.0
- @bx-ui-framework/common@15.0.0
- manager-thedate@1.0.16
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.