express-router-engine@3.6.6
Malicious code in express-router-engine (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
express-router-engine@3.6.6 is a combosquat package impersonating the Express ecosystem. On require(), it fetches a remote payload from hxxps://www[.]jsonkeeper[.]com/b/JTOGJ and executes the "cookie" field of the response as arbitrary JavaScript code via the Function constructor, passing the Node.js require() function to the payload. This gives the attacker full control over the runtime environment to execute any second-stage commands, exfiltrate data, or install further malware. The C2 endpoint is jsonkeeper[.]com at path /b/JTOGJ.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 01:54 PM
- analyzed
- Jul 9, 2026, 01:54 PM
Related advisories
- type-slint@3.3.7
- chai-as-smart@2.3.5
- vite-pwa-config@1.1.1
- cookie-js-ease@2.1.7
- polymarket-kelly-stake-math@3.6.1
- polymarket-kit@2.4.1
- chai-as-const@1.4.5
- uncaxss@1.3.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.