express-middle@5.5.1
Malicious code in express-middle (npm)
Analysis
Package express-middle@5.5.1 is a combosquat of the popular Express framework. On install, the postinstall hook runs a heavily obfuscated index.js that: (1) requires child_process, fs, and os; (2) constructs a hidden file path under the user's home directory by splitting a string on '.' characters; (3) writes a decoded payload to that path; (4) spawns a detached child process executing the dropped file with windowsHide enabled. The package has no repository URL and its README is titled "Safe Wrapper Module" (not express-middle), warning users to "avoid production deployment" and "inspect child_process usage" — a disclaimer on a combosquat package acting as a dropper.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 07:40 PM
- analyzed
- Jul 29, 2026, 07:41 PM
Related advisories
- streak-grid-core@1.0.0
- type-unique@3.1.3
- type-astr@3.2.3
- type-atob@3.3.7
- testis-pack@1.0.0
- express-mongo-limit@2.0.1
- notifier-utils@1.3.7
- chai-as-staged@6.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.