LWA-2026-6635 MAL-2026-10414 ↗ confirmed malware

express-request-engine@3.6.3

Malicious code in express-request-engine (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

express-request-engine@3.6.3 is a combosquat of the "express" framework. When required, it fetches attacker-controlled code from hxxps://api[.]jsonbin[.]io/v3/b/6a4f5816f5f4af5e29762c92 and executes it via the Function constructor with full require() access, giving the attacker arbitrary code execution in the installer's Node.js process. The C2 endpoint is a jsonbin[.]io bin whose content the attacker can update at any time to serve different payloads.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 10:38 AM
analyzed
Jul 12, 2026, 10:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.