LWA-2026-11721 confirmed malware

express-helmet@0.0.1

Malicious code in express-helmet (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

express-helmet@0.0.1 is a combosquat of the popular helmet package: it uses the name express-helmet and mirrors helmet's description, repository, and homepage while shipping a verbatim copy of helmet's source (CSP and HTTP-header middleware in index.cjs/index.mjs). The package is published under a name designed to impersonate the legitimate helmet package, which can lead installers to pull it in place of the real one. The current version's code is a clean copy with no lifecycle hooks, no network activity, and no credential access.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 11:00 AM
analyzed
Aug 29, 2026, 11:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.