SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Remote code execution, persistence, self-deletion, and obfuscation found in the package's code confirm its malicious nature.

Verification Record

Remote code execution, persistence, self-deletion, and obfuscation found in the package's code

Details

Note: This report is updated by a verification record

The package express-cookie-parser (version 1.4.12) exhibits strong indicators of malicious behavior based on the LLM-based file analysis. Evidence 0, 1, and 2 reveal critical functionalities: remote code execution from a GitHub URL (Evidence 0), persistence through the creation of a startup script (Evidence 1), and self-deletion to hinder analysis (Evidence 2). These actions, combined with obfuscation techniques (Evidence 3) to mask the malicious intent, strongly suggest malicious activity. While the lack of project information (Evidence 4) is concerning and increases suspicion, the LLM findings are sufficient to classify this package as malware. The remote code execution capability alone is a significant threat, allowing an attacker to compromise systems and execute arbitrary code. The persistence mechanism ensures the malware's survival even after a reboot. The self-deletion attempts to evade detection and analysis. The combination of these factors makes this a clear case of malicious software.

express-cookie-parser@1.4.12Malicious
Verified
Analysed at: 4/23/25, 8:31 AM
Source: https://registry.npmjs.org/express-cookie-parser/-/express-cookie-parser-1.4.12.tgz
SHA256: 511d911e4d6812987e6c90cf49b9bfcf29337d3b81dcab19b1000500ca8812f6
Confidence: High