Malicious code in express-middle (npm)
The npm package 'express-middle' version 5.5.1 contains malicious code that executes remote code on the installer's machine during installation. The package declares a postinstall script that runs an obfuscated JavaScript file which contacts a hidden command-and-control server, decrypts a payload, writes it to disk, and executes it silently. The package does not provide any legitimate middleware functionality and is designed solely to enable remote code execution.
AI Analysis
Technical Summary
The 'express-middle' npm package version 5.5.1 includes a postinstall script that triggers automatically upon installation. This script runs an obfuscated JavaScript file that dynamically constructs an IPv4 address to contact a remote HTTPS server. It retrieves an encrypted payload, decrypts it using AES with a key derived via PBKDF2, writes the decrypted payload to disk, and executes it using child_process.exec with the console window hidden. The package masquerades as middleware for Express but contains no legitimate functionality, serving only to enable remote code execution under attacker control.
Potential Impact
Installing the 'express-middle' package version 5.5.1 results in remote code execution on the installer's machine, allowing an attacker to run arbitrary code with the privileges of the user performing the installation. This can lead to full compromise of the affected system.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing the 'express-middle' package version 5.5.1. Verify package authenticity before installation and prefer well-known, trusted packages. Monitor for any updates or advisories from the package maintainers or npm registry regarding this issue.
Malicious code in express-middle (npm)
Description
The npm package 'express-middle' version 5.5.1 contains malicious code that executes remote code on the installer's machine during installation. The package declares a postinstall script that runs an obfuscated JavaScript file which contacts a hidden command-and-control server, decrypts a payload, writes it to disk, and executes it silently. The package does not provide any legitimate middleware functionality and is designed solely to enable remote code execution.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'express-middle' npm package version 5.5.1 includes a postinstall script that triggers automatically upon installation. This script runs an obfuscated JavaScript file that dynamically constructs an IPv4 address to contact a remote HTTPS server. It retrieves an encrypted payload, decrypts it using AES with a key derived via PBKDF2, writes the decrypted payload to disk, and executes it using child_process.exec with the console window hidden. The package masquerades as middleware for Express but contains no legitimate functionality, serving only to enable remote code execution under attacker control.
Potential Impact
Installing the 'express-middle' package version 5.5.1 results in remote code execution on the installer's machine, allowing an attacker to run arbitrary code with the privileges of the user performing the installation. This can lead to full compromise of the affected system.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing the 'express-middle' package version 5.5.1. Verify package authenticity before installation and prefer well-known, trusted packages. Monitor for any updates or advisories from the package maintainers or npm registry regarding this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12376
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735744bf8831d539159cae
Added to database: 08/05/2026, 15:31:16 UTC
Last enriched: 08/05/2026, 17:21:08 UTC
Last updated: 08/05/2026, 17:21:08 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.