MAL-2026-6523

    Dashboard / Malicious Package / MAL-2026-6523

    MAL-2026-6523

    Published: 26 Jun 2026Last Modified: 26 Jun 2026

    Summary: Malicious code in express-plugin (npm)

    Details: Source: amazon-inspector (183cda19ef38d3451b375669fb460577a83217091d96d7fc11d5bf33679c8003) On module load, index.js auto-invokes initPlugin(), which HTTP-GETs https://jsonkeeper.com/b/PRA3O, parses the JSON response, and passes the response's `cookie` field to `Function.constructor` with `require` exposed, then immediately invokes the resulting function. Any process that does `require('express-plugin')` executes arbitrary JavaScript pulled from a mutable third-party paste host with full Node `require` privileges, giving the operator of that paste full control of the installer's machine. The file is headed as `normalize-path (ES6 safe version)` and exports an unused normalizePath function as decoy; the package name `express-plugin` is cover framing intended to make the package look like a benign Express middleware. The remote payload is attacker-mutable: today's content can be swapped for credential theft, persistence, or any other action at any time without republishing the package.

    Affected packages

    Package

    Name: express-plugin

    Purl: pkg:npm/express-plugin

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.6.6