LWA-2026-6388 MAL-2026-7012 ↗ confirmed malware

express-mongo-limit@2.0.1

Malicious code in express-mongo-limit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1543.002 · Systemd ServiceT1055 · Process InjectionT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1115 · Clipboard DataT1113 · Screen CaptureT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1641 · Clipboard Modification

Analysis

express-mongo-limit is a combosquat of the legitimate express-mongo-sanitize package. On install, the postinstall hook runs index.js which: (1) installs clipboardy and screenshot-desktop globally, (2) starts a crypto-clipper (service.js) that monitors the clipboard every second and replaces Ethereum (0x...), Bitcoin (bc1.../1.../3...), Solana, and Tron wallet addresses with the attacker's addresses — 0x62Fc857DE5469fDd81F57F309c2fb000cad7bbbb (ETH), bc1q8tzzpun6rd45s6fgar2up8nfelt4u2r2h999cc (BTC), 6A7vQWJveJBWP78oktAjoZbMakrCAQyLphJ5Kswy5xA4 (SOL), TUqk5th1eXZWrt1arsqpxZ3frqaCxc9Lr4 (TRX), (3) captures screenshots every 2 seconds and emails them to [account] via nodemailer, (4) exfiltrates all environment variables (process.env) via POST to hxxps://ipcheck-six[.]vercel[.]app/api, (5) registers PM2 startup for persistence. A commented-out code block would fetch from hxxps://gamboracle[.]vercel[.]app/api and execute the response via new Function() — a remote code execution channel.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 09:18 AM
analyzed
Jul 7, 2026, 09:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.