Malicious code in electro-session (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e7c16137bdd5ac7c97d450fb8ff77103d9c6421f78848b1017f84348c6ec3762) [email protected] presents itself as 'Session utilities' (~170-byte README) but ships ~1MB of heavily obfuscated JavaScript under dist/ (index.js, cli.js, run-once.js, schedule.js), all produced by javascript-obfuscator (listed in devDependencies) using an RC4-encrypted string array, rotating index accessor, and self-defending/debug-protection wrappers that hide every string, module path, URL, and file path. dist/index.js imports node:sqlite, node:fs, node:os, node:path, node:child_process, node:crypto and requires./schedule; package.json pins engines.node to >=22.5.0 (the release that introduced the built-in node:sqlite API) and declares @vercel/blob as a runtime dependency. The combination — built-in SQLite reader + child_process + crypto + a cloud blob upload SDK, wrapped in anti-analysis obfuscation — matches the fingerprint of an infostealer that reads local SQLite-backed credential/session stores (browser Login Data / Cookies / History, wallet extensions, chat app session DBs), decrypts them via child_process-invoked OS primitives, and uploads them via @vercel/blob. dist/schedule.js (imported by index.js) and the sibling dist/run-once.js implement the standard schedule-plus-payload persistence split via node:child_process, consistent with registering a recurring OS task (schtasks/cron/launchctl) that re-invokes run-once.js. There are no npm install lifecycle hooks; the payload is triggered when a developer runs the electro-session bin (dist/cli.js prompts a bilingual y/yes/s/si affirmative — English plus Spanish, indicating targeting of Spanish-speaking developers — then constructs new Sessions({...:true,...:true})), or when any module does require('electro-session') and instantiates Sessions (run-once.js does so unconditionally).
Malicious code in electro-session (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e7c16137bdd5ac7c97d450fb8ff77103d9c6421f78848b1017f84348c6ec3762) [email protected] presents itself as 'Session utilities' (~170-byte README) but ships ~1MB of heavily obfuscated JavaScript under dist/ (index.js, cli.js, run-once.js, schedule.js), all produced by javascript-obfuscator (listed in devDependencies) using an RC4-encrypted string array, rotating index accessor, and self-defending/debug-protection wrappers that hide every string, module path, URL, and file path. dist/index.js imports node:sqlite, node:fs, node:os, node:path, node:child_process, node:crypto and requires./schedule; package.json pins engines.node to >=22.5.0 (the release that introduced the built-in node:sqlite API) and declares @vercel/blob as a runtime dependency. The combination — built-in SQLite reader + child_process + crypto + a cloud blob upload SDK, wrapped in anti-analysis obfuscation — matches the fingerprint of an infostealer that reads local SQLite-backed credential/session stores (browser Login Data / Cookies / History, wallet extensions, chat app session DBs), decrypts them via child_process-invoked OS primitives, and uploads them via @vercel/blob. dist/schedule.js (imported by index.js) and the sibling dist/run-once.js implement the standard schedule-plus-payload persistence split via node:child_process, consistent with registering a recurring OS task (schtasks/cron/launchctl) that re-invokes run-once.js. There are no npm install lifecycle hooks; the payload is triggered when a developer runs the electro-session bin (dist/cli.js prompts a bilingual y/yes/s/si affirmative — English plus Spanish, indicating targeting of Spanish-speaking developers — then constructs new Sessions({...:true,...:true})), or when any module does require('electro-session') and instantiates Sessions (run-once.js does so unconditionally).
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14242
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4c0acd9273b4925243d
Added to database: 08/19/2026, 13:50:56 UTC
Last updated: 08/19/2026, 13:51:34 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.