session-exp@1.3.20
Malicious code in session-exp (npm)
Analysis
Combosquat of the popular express-session package. On require(), the module session/cookie.js decodes a Base64 string to hxxps://api[.]npoint[.]io/cbbe4c31888c0fcfbdd8, fetches a JSON payload from that URL using the axios HTTP library, and executes eval(res.data.cookie) — providing the attacker with arbitrary remote code execution inside the installer's process. The payload URL is hosted on npoint[.]io (a free JSON hosting service), so the attacker can change the delivered payload at any time without republishing the package. The README markets the package for blockchain applications, likely to target crypto wallet environments.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 07:33 PM
- analyzed
- Jun 13, 2026, 07:33 PM
Related advisories
- mailconfirmer@3.3.12
- server-up-ndot@1.0.0
- sentrykit@30.0.0
- search-reservation@55.0.0
- rollup-runtime-polyfill-core@0.13.5
- rollup-packages-polyfill-core@0.5.0
- rollup-plugin-polyfill-connect@1.0.1
- ring-device-settings-library@45.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.