LWA-2026-4296 MAL-2026-6543 ↗ confirmed malware

express-initial@12.1.7

Malicious code in express-initial (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1204.002 · Malicious FileT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or Location

Analysis

Package express-initial@12.1.7 is a combosquat of the popular express framework, published by [account] who previously published the confirmed-malicious package xnder-sdk-js. The postinstall hook runs a heavily obfuscated index.js (javascript-obfuscator style, RC4-like string decryption, opaque numeric constants). The code loads child_process, fs, and path modules, constructs a URL from decoded strings, fetches a payload from a remote host, writes it to disk via writeFileSync, and then spawns the downloaded file via child_process.spawn with windowsHide:true — a classic second-stage dropper pattern.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 01:36 PM
analyzed
Jun 11, 2026, 01:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.