express-plugin@1.6.6
Malicious code in express-plugin (npm)
Analysis
The package express-plugin@1.6.6 is a remote code execution downloader. On require(), it fetches JSON from hxxps://jsonkeeper[.]com/b/PRA3O, extracts the "cookie" field from the response, and passes it to the Function constructor to dynamically create and execute arbitrary remote code. The newly-constructed function receives the Node.js `require` module as an argument, giving the C2-controlled payload full access to read the filesystem, environment variables, and installed modules. The package has no declared dependencies and its only file is a stub with stolen code comments from the normalize-path project. The payload hosting URL is jsonkeeper[.]com/b/PRA3O.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 01:35 PM
- analyzed
- Jun 26, 2026, 01:36 PM
Related advisories
- dtxto1ols@1.0.2
- ts-einkle@1.0.9
- dtxtools@1.0.0
- dttfdsdee@1.0.1
- @salem_jalal/osc-components@1981.17.7
- data-parser-utils@3.0.2
- dttsdee@1.0.0
- dddooo@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.