cookie-parser-jsnpm
Advisory published Updated
cookie-parser-js is a confirmed malicious npm package (MAL-2026-10060) that typosquats a legitimate package to trick installs (malicious versions 1.0.8, 1.4.8, 1.4.9…). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in cookie-parser-js (npm)
What this malware does
cookie-parser-js impersonates the widely used cookie-parser package: it copies TJ Holowaychuk / Doug Wilson author metadata, the description, the README (which self-identifies as cookie-parser-ease), and the expressjs repository slug. package.json declares an undocumented runtime dependency cookie-js-ease pinned to the mutable tag latest, and index.js does var Cookies = require('cookie-js-ease'); Cookies.set("", "", {expires: 0}) inside the exported cookieParser factory. The Cookies.set call passes empty key/value with expires:0 — a functional no-op whose only effect is to force load and execute the transitive dependency when a consumer requires('cookie-parser-js') and invokes the middleware. cookie-js-ease is not a known cookie library and appears fabricated to serve as the payload carrier: because it is pinned to latest, its author (controlled by the same actor) can push arbitrary code at any time, giving them code execution inside any consumer application that loads this middleware. The name-similarity to cookie-parser (a top-download express middleware) plus the borrowed identity of its real maintainers is a deliberate confusion attack targeting developers who mistype the package name.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for cookie-parser-js (7 malicious versions).
If you installed it — respond
cookie-parser-js is a typosquat — you almost certainly intended a legitimately-named package. Remove cookie-parser-js, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If cookie-parser-js was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks cookie-parser-js-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.