LWA-2026-7081 MAL-2026-13368 ↗ confirmed malware

express-dever@5.1.7

Malicious code in express-dever (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1564.003 · Hidden WindowT1485 · Data Destruction

Analysis

express-dever@5.1.7 is a combosquat of the express framework. The postinstall hook runs a heavily obfuscated 20KB JavaScript payload that requires child_process, fs, os, and path; spawns processes with windowsHide:true to execute stealthily; suppresses error handlers (uncaughtException, unhandledRejection); and writes files to disk. The obfuscated code contains encoded payload strings and uses a complex async execution flow. The package has no repository and its README warns the script is obfuscated and recommends sandboxing — a deflection tactic. The dependency express-env@^1.0.4 is also suspiciously named.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 07:41 AM
analyzed
Jul 24, 2026, 07:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.