express-initial@12.1.7
Malicious code in express-initial (npm)
Analysis
Package express-initial@12.1.7 is a combosquat of the popular express framework, published by [account] who previously published the confirmed-malicious package xnder-sdk-js. The postinstall hook runs a heavily obfuscated index.js (javascript-obfuscator style, RC4-like string decryption, opaque numeric constants). The code loads child_process, fs, and path modules, constructs a URL from decoded strings, fetches a payload from a remote host, writes it to disk via writeFileSync, and then spawns the downloaded file via child_process.spawn with windowsHide:true — a classic second-stage dropper pattern.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 01:36 PM
- analyzed
- Jun 11, 2026, 01:38 PM
Related advisories
- node-gyp-runtime@1.0.0
- mjs-biginteger@5.0.6
- vite-config-optimizer@1.1.4
- bigops-chat-transfer@35.3.6
- tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci@20.1.2
- twork-products-taiga2-products-timeline@20.6.1
- beaver-ui-actions-button@5.4.7
- fdd41@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.