malware npm

express-session-js

discovered 2026-04-02

express-session-js is identified in the SafeDep analysis "Malicious npm Package express-session-js Drops Full RAT Payload". A malicious npm package typosquatting express-session fetches and executes a full Remote Access Trojan from a paste service, targeting browser credentials, crypto wallets, SSH keys, and more.

Threat types

rat credential_stealer crypto_drainer data_exfiltration c2_agent

Malicious versions

  • 1.19.0

Campaigns

Indicators

Techniques

Read the full analysis →