express-request-engine@3.6.3
Malicious code in express-request-engine (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
express-request-engine@3.6.3 is a combosquat of the "express" framework. When required, it fetches attacker-controlled code from hxxps://api[.]jsonbin[.]io/v3/b/6a4f5816f5f4af5e29762c92 and executes it via the Function constructor with full require() access, giving the attacker arbitrary code execution in the installer's Node.js process. The C2 endpoint is a jsonbin[.]io bin whose content the attacker can update at any time to serve different payloads.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 10:38 AM
- analyzed
- Jul 12, 2026, 10:39 AM
Related advisories
- @kkael/baileys@8.0.8
- dotnet-runtime-base@1.0.5
- frontend-regulations@99.9.1
- sso-users-detection@99.9.1
- tinyparrot@0.4.1
- svg-fetcher@2.4.1
- cookie-sign@2.3.5
- react-hot-svg@1.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.