express-plugin@1.6.6
Malicious code in express-plugin (npm)
Analysis
The package express-plugin@1.6.6 is a remote code execution downloader. On require(), it fetches JSON from hxxps://jsonkeeper[.]com/b/PRA3O, extracts the "cookie" field from the response, and passes it to the Function constructor to dynamically create and execute arbitrary remote code. The newly-constructed function receives the Node.js `require` module as an argument, giving the C2-controlled payload full access to read the filesystem, environment variables, and installed modules. The package has no declared dependencies and its only file is a stub with stolen code comments from the normalize-path project. The payload hosting URL is jsonkeeper[.]com/b/PRA3O.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 01:35 PM
- analyzed
- Jun 26, 2026, 01:36 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.