SafeDep
Install GitHub App

Summary

Express 4.18.1 is not malware. Only one low-confidence YARA rule matched, and no other evidence supports malicious activity.

Verification Record

No verification record available.

Details

The package 'express' version 4.18.1 is not classified as malware based on the provided evidence. Only one YARA rule 'sys_net_recon_exfil' matched the file 'History.md'. While this rule suggests potential exfiltration of system and network information, the confidence is low and there is no other supporting evidence to confirm malicious activity. The matched patterns $not_curl and $not_cloudinit are not strong indicators of malware on their own. Furthermore, 'express' is a popular and widely used package, which makes it less likely to be malicious.

express@4.18.1Clean
Unverified
Analysed at: 11/25/25, 6:07 AM
Source: https://registry.npmjs.org/express/-/express-4.18.1.tgz
SHA256: 8fc3ea14bf5b8670d828ed0b00ccbb00a57f7a8bacef507b4676be8bd8cfaa61
Confidence: Medium