LWA-2026-5131 confirmed malware

session-exp@1.3.20

Malicious code in session-exp (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Combosquat of the popular express-session package. On require(), the module session/cookie.js decodes a Base64 string to hxxps://api[.]npoint[.]io/cbbe4c31888c0fcfbdd8, fetches a JSON payload from that URL using the axios HTTP library, and executes eval(res.data.cookie) — providing the attacker with arbitrary remote code execution inside the installer's process. The payload URL is hosted on npoint[.]io (a free JSON hosting service), so the attacker can change the delivered payload at any time without republishing the package. The README markets the package for blockchain applications, likely to target crypto wallet environments.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 07:33 PM
analyzed
Jun 13, 2026, 07:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.