winston-js-express@1.0.5
Malicious code in winston-js-express (npm)
Analysis
Package winston-js-express is a trojanized clone of the legitimate winston-express logging middleware. It copies the real middleware source code but injects require("es6-runtimejs") (line 46 of index.js) which loads a known-malicious dependency that has since been removed from npm. The package name combosquats "winston" and "express" to appear legitimate. The malware executes automatically when the package is imported into a Node.js application (module load time, not install time). The publisher used email [account] and has published exclusively malicious packages.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 03:58 AM
- analyzed
- Jun 16, 2026, 03:59 AM
Related advisories
- wind_css@4.0.13
- pretie_x2@3.8.5
- web-streams-shim@1.0.0
- pretie_x1@3.8.5
- wordpad-text-ui@1.0.0
- check-ulid@3.0.2
- webpack-cdn-fetcher@1.0.1
- web3-core-utils@4.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.