malware npm

routecraft

discovered 2026-06-17

Express typosquat that clones the full express dependency tree. preinstall hook 'node ./lib/configure.js' checks Node>=18, then require('procwire') only when os.platform()==='win32' && nodeVersion>=18, dragging the dropper in only on Windows. Armed on first publish (no clean precursor version), so it does NOT match the clean-then-armed subpattern. Maintainer [email protected], fabricated GitHub org akuznetsov-oss.

Threat types

typosquat other

Malicious versions

  • 4.2.0 · 5ad9fae3bb6397d3…

Campaigns

Indicators

Techniques

Read the full analysis →