malware npm
routecraft
discovered 2026-06-17Express typosquat that clones the full express dependency tree. preinstall hook 'node ./lib/configure.js' checks Node>=18, then require('procwire') only when os.platform()==='win32' && nodeVersion>=18, dragging the dropper in only on Windows. Armed on first publish (no clean precursor version), so it does NOT match the clean-then-armed subpattern. Maintainer [email protected], fabricated GitHub org akuznetsov-oss.
Threat types
typosquat other
Malicious versions
- 4.2.0 · 5ad9fae3bb6397d3…
