OSV ID
MAL-2026-17247
Ecosystem
npm
Summary
exptredd@5.2.3 is published under a name resembling express and ships express's package metadata (description, author, contributors, repository, homepage, keywords, dependency list) verbatim as a cover for a malicious install-time payload. package.json line 98 defines a preinstall lifecycle script that uses curl to fetch an unpinned remote JavaScript file from an anonymous gitflic.ru project (hellscripter/install-scripts) proxied via web.archive.org and pipes the response directly into node, executing attacker-controlled code on the installer's host during npm install. The fetch destination is unrelated to express's publisher, is not pinned by hash or version, and is served over a mutable archive URL whose content the attacker controls. The combination of name-confusion with express, verbatim express metadata as disguise, and an install-time curl|node dropper to a non-publisher host is a confirmed install-time remote code execution against any developer or build system that runs npm install on this package.
Source: amazon-inspector (906cb705c9e58527d888fca6e046fafb5586b0529f989496d96a92a5450f0e7c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.