express-mocha-test@0.0.1
Malicious code in express-mocha-test (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
express-mocha-test is a combosquat package impersonating the Express and Mocha project names. The postinstall hook (scripts/postinstall.cjs) calls an onInstall() function in index.cjs. This function fetches code from hxxps://2939e69fc408[.]ngrok-free[.]app/stats and executes it immediately via eval(), making it a second-stage payload downloader. The attacker can serve arbitrary malicious code from that endpoint on every install. The package has no functional relationship to its name or its stated description ("Integrate redis with cookies").
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 04:00 AM
- analyzed
- Jun 29, 2026, 04:01 AM
Related advisories
- date-uuid@1.0.1
- pkg-fallback@1.1.0
- @pisell/pisellos@2.2.172
- mailconfirmer@3.3.11
- weavedb-base@0.45.3
- friendly-greeter-demo@1.0.10
- ts-ankle@1.1.0
- @ranstech/baileys@6.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.