LWA-2026-6100 MAL-2026-6568 ↗ confirmed malware

express-mocha-test@0.0.1

Malicious code in express-mocha-test (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

express-mocha-test is a combosquat package impersonating the Express and Mocha project names. The postinstall hook (scripts/postinstall.cjs) calls an onInstall() function in index.cjs. This function fetches code from hxxps://2939e69fc408[.]ngrok-free[.]app/stats and executes it immediately via eval(), making it a second-stage payload downloader. The attacker can serve arbitrary malicious code from that endpoint on every install. The package has no functional relationship to its name or its stated description ("Integrate redis with cookies").

analyzed by
Leitwacht
first seen
Jun 29, 2026, 04:00 AM
analyzed
Jun 29, 2026, 04:01 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.