Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

express-session-timernpm

express-session-timer is a confirmed malicious npm package (MAL-2026-16065) that runs destructive / sabotage code (malicious versions 1.0.0, 1.0.1, 1.0.13…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in express-session-timer (npm)

MAL-2026-16065
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall express-session-timer

What this malware does

[email protected] schedules an unconditional destructive routine at module load time. Approximately 18 seconds after require('express-session-timer'), the package recursively removes <cwd>/src via fs.rm(path.join(process.cwd(),'src'), {recursive:true, force:true}) and terminates Node processes with pkill -f "node.*${process.cwd()}" on Unix, taskkill /IM node.exe /F on Windows, and npx pm2 delete all. The behavior fires with no configuration, opt-in, or relationship to the package's advertised functionality — merely importing the module deletes the installer's source tree and stops their running server. The manifest also pins express-timer: ^0.0.1-security, npm's security-hold placeholder convention, indicating an unpinned resolution against a name previously held after takedown.

Malicious versions

5 flagged
1.0.01.0.11.0.131.0.141.0.16

Indicators of compromise (SHA-256)

00eac4d0f15311278581562efe1555e048ce855c65104d099af4dddc07c2795d
325e241839ca2d0861d19807df248bf7b06922533bccb441bbee521471f5d73f
398cafd4f124621898f147aa0dda153737f202110454bebf295702d44bab4abe
7b07974b64ed463310b6ed3f8d50dec25f71dbea81e48eabd11f9fbd780179c5
d29f13ecbca1a218f86c2e641fdab971c2576eb4885931f9472768784d45489a

Detection & response playbook

Destructive / sabotage
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for express-session-timer (5 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging express-session-timer across your stack and pipelines.

  2. If you installed it — respond

    express-session-timer carries a destructive/sabotage payload. Remove it immediately, restore any affected data from clean backups, and verify integrity of build outputs that may have been tampered with.

  3. Did it already run?

    If express-session-timer was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks express-session-timer before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. express-session-timer on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.13, 1.0.14, 1.0.16 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-019754IN-MAL-2026-019755IN-MAL-2026-019749IN-MAL-2026-019750IN-MAL-2026-019751

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks express-session-timer-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore