Package impersonates legitimate express-session package; initPlugin() downloads and executes attacker-controlled remote code on startup via new Function.constructor()
-= Per source details. Do not edit below this line.=-
The package express-session-js was found to contain malicious code.
{
"malicious-packages-origins": [
{
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"sha256": "853f35820c1bfb3bd8be7548debc48dbf86de52a43e91d7b586a9b1ce86a54c7",
"source": "amazon-inspector",
"modified_time": "2026-04-07T14:24:50Z",
"import_time": "2026-04-07T14:39:24.981649905Z"
}
]
}