LWA-2026-6467 confirmed malware
express-route-engine@3.6.6
Malicious code in express-route-engine (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File
Analysis
express-route-engine@3.6.6 is a combosquat package impersonating the Express.js ecosystem. The single entry point (index.js) is heavily obfuscated with javascript-obfuscator. At runtime it requires child_process, os, fs, and path modules; spawns a hidden child process; makes an HTTP request to a remote server with an Authentication header; decodes the response using Buffer.from(); writes the decoded content to a file; and executes the downloaded payload. This is a C2 download-and-exec implant that runs on require().
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 05:50 PM
- analyzed
- Jul 8, 2026, 05:52 PM
Related advisories
- testudo-pack@1.0.0
- testis-pack@1.0.0
- @vite-ln/build-ts@5.17.0
- @vite-tab/tab@5.7.0
- @bobfrankston/msger@0.1.388
- react-icons-svgo@1.5.4
- npm-rce-poc@1.0.13
- @withoneltd/lucky@0.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.