LWA-2026-6467 confirmed malware

express-route-engine@3.6.6

Malicious code in express-route-engine (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

express-route-engine@3.6.6 is a combosquat package impersonating the Express.js ecosystem. The single entry point (index.js) is heavily obfuscated with javascript-obfuscator. At runtime it requires child_process, os, fs, and path modules; spawns a hidden child process; makes an HTTP request to a remote server with an Authentication header; decodes the response using Buffer.from(); writes the decoded content to a file; and executes the downloaded payload. This is a C2 download-and-exec implant that runs on require().

analyzed by
Leitwacht
first seen
Jul 8, 2026, 05:50 PM
analyzed
Jul 8, 2026, 05:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.