LWA-2026-7233 MAL-2026-12376 ↗ confirmed malware

express-middle@5.5.1

Malicious code in express-middle (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1204.002 · Malicious FileT1055 · Process InjectionT1027 · Obfuscated Files or InformationT1105 · Ingress Tool Transfer

Analysis

Package express-middle@5.5.1 is a combosquat of the popular Express framework. On install, the postinstall hook runs a heavily obfuscated index.js that: (1) requires child_process, fs, and os; (2) constructs a hidden file path under the user's home directory by splitting a string on '.' characters; (3) writes a decoded payload to that path; (4) spawns a detached child process executing the dropped file with windowsHide enabled. The package has no repository URL and its README is titled "Safe Wrapper Module" (not express-middle), warning users to "avoid production deployment" and "inspect child_process usage" — a disclaimer on a combosquat package acting as a dropper.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 07:40 PM
analyzed
Jul 29, 2026, 07:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.