express-dever@5.1.7
Malicious code in express-dever (npm)
Analysis
express-dever@5.1.7 is a combosquat of the express framework. The postinstall hook runs a heavily obfuscated 20KB JavaScript payload that requires child_process, fs, os, and path; spawns processes with windowsHide:true to execute stealthily; suppresses error handlers (uncaughtException, unhandledRejection); and writes files to disk. The obfuscated code contains encoded payload strings and uses a complex async execution flow. The package has no repository and its README warns the script is obfuscated and recommends sandboxing — a deflection tactic. The dependency express-env@^1.0.4 is also suspiciously named.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 07:41 AM
- analyzed
- Jul 24, 2026, 07:43 AM
Related advisories
- @web3-helpers/core@1.0.5
- theme-color-picker@2.0.28
- vue-plugin-bomb@1.0.1
- vourfly-tele@4.7.6
- vite-plugin-vue-extend@1.0.9
- vite-plugin-bomb-extend@2.0.0
- vite-plugin-bomb@2.0.0
- super-test-json@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.