Skip to main content

Malicious code in express-request-engine (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 06:55:20 UTC)
Source: GCVE Database
Product: express-request-engine

Description

The npm package express-request-engine version 3.6.3 contains malicious code that executes arbitrary attacker-controlled JavaScript upon module load. The package masquerades as a normalize-path utility but performs a network fetch to a mutable external JSON resource and executes code from it using the Function constructor. This results in full module-loading privileges being granted to attacker-controlled code. Any system with this package installed should be considered fully compromised.

Affected software

npmghsa
express-request-engine
Affected versions
=3.6.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 16:57:29 UTC

Technical Analysis

The express-request-engine npm package (version 3.6.3) is a malicious package that disguises itself as a normalize-path utility. Upon loading, it calls an initialization function that fetches data from a mutable JSON document hosted on jsonbin.io. It extracts a field named 'cerookie' from the response and executes it as JavaScript code using the Function constructor, passing in the consumer's require function. This allows arbitrary attacker-controlled code to run with full privileges within the importing process. The external JSON resource is mutable and controlled by an anonymous account, enabling the attacker to change the executed payload at any time. The obfuscation in naming and the mismatch between advertised functionality and actual behavior indicate deliberate concealment rather than accidental misconfiguration.

Potential Impact

Systems that have installed or are running express-request-engine version 3.6.3 are fully compromised. The attacker gains the ability to execute arbitrary code with full module-loading privileges, potentially leading to complete system compromise. All secrets and keys stored on the affected system should be considered exposed and must be rotated immediately. Removing the package alone may not be sufficient to eradicate the compromise, as the attacker may have installed additional malicious software.

Mitigation Recommendations

Remove the express-request-engine package version 3.6.3 immediately from all affected systems. Rotate all secrets, credentials, and keys that were stored or accessible on the compromised systems using a secure, unaffected environment. Conduct a thorough investigation and remediation of the affected systems to detect and remove any additional malicious software or persistence mechanisms. Patch status is not applicable as this is a malicious package rather than a vulnerability with an official fix. Avoid installing packages from untrusted or unknown sources and verify package integrity before use.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10414
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a54ad9c68715ace438f3ce3

Added to database: 07/13/2026, 09:19:24 UTC

Last enriched: 08/20/2026, 16:57:29 UTC

Last updated: 09/07/2026, 18:45:31 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses