@rmejia32/malicious_package_demo
v1.0.0
Published
Demo-only package showing how malicious npm packages can behave (safe).
Downloads
25
Maintainers
Readme
@rmejia32/malicious_package_demo
This is a demo package created to demonstrate how a malicious dependency could behave inside a Node.js / Express application.
It’s safe — nothing is actually exfiltrated — and is intended purely for educational use.
Prerequisites
- Node.js ≥ 18
- Express and express-session (in the host app)
Installation
Add this as a local dependency in your demo project:
npm install @rmejia32/malicious_package_demoUsage
Import the middleware:
import { installSnoop } from "@rmejia32/malicious_package_demo";Mount it after your middleware:
app.use(session(sessionOptions)); app.use(installSnoop(sessionOptions));
Disclaimer
This package is for demonstration and educational purposes only. It performs no network activity and does not collect or transmit any real data.
