express-guardian@1.4.1
Malicious code in express-guardian (npm)
Analysis
express-guardian is a combosquat package impersonating Express security middleware. When required, it spawns a detached child process that makes an HTTP GET request to hxxp://server-genimi-check[.]vercel[.]app/defy/v3 with a hardcoded authorization header. If the server responds with HTTP 404 and a JSON body containing a 'token' field, that token is executed as arbitrary JavaScript code via the Function constructor, granting the attacker full remote code execution on the installer's machine. The package's README fraudulently claims to provide SQL injection detection, XSS protection, and request sanitization — none of this functionality exists in the code. C2 endpoint: server-genimi-check[.]vercel[.]app, path /defy/v3.
- analyzed by
- Leitwacht
- first seen
- Jul 6, 2026, 07:47 PM
- analyzed
- Jul 6, 2026, 07:48 PM
Related advisories
- chai-sdk@1.4.7
- zredis-typed@1.0.127
- luludawang-kit@0.0.1
- express-ini@12.1.10
- db-query-log@1.0.2
- @marketfront/fingerprint@7.0.0
- @marketfront/basemarkettemplate@7.0.0
- @marketfront/bannerpopup@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.