LWA-2026-6004 MAL-2026-6523 ↗ confirmed malware

express-plugin@1.6.6

Malicious code in express-plugin (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1082 · System Information Discovery

Analysis

The package express-plugin@1.6.6 is a remote code execution downloader. On require(), it fetches JSON from hxxps://jsonkeeper[.]com/b/PRA3O, extracts the "cookie" field from the response, and passes it to the Function constructor to dynamically create and execute arbitrary remote code. The newly-constructed function receives the Node.js `require` module as an argument, giving the C2-controlled payload full access to read the filesystem, environment variables, and installed modules. The package has no declared dependencies and its only file is a stub with stolen code comments from the normalize-path project. The payload hosting URL is jsonkeeper[.]com/b/PRA3O.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 01:35 PM
analyzed
Jun 26, 2026, 01:36 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.