MAL-2026-2445

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pro-express/MAL-2026-2445.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2445
Published
2026-04-02T15:21:37Z
Modified
2026-04-07T14:55:23.292574Z
Summary
Malicious code in pro-express (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (508e68df7788049a51c684d3038db25fb043a5dda88579108c5eb49eacbfff95)

The package pro-express was found to contain malicious code.

Source: ossf-package-analysis (c449b795f84201195315183f1bb5c85b932f39c9cce1260225aec17eee7c8344)

The OpenSSF Package Analysis project identified 'pro-express' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "c449b795f84201195315183f1bb5c85b932f39c9cce1260225aec17eee7c8344",
            "modified_time": "2026-04-02T15:21:37Z",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-04-03T05:59:53.222142013Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "508e68df7788049a51c684d3038db25fb043a5dda88579108c5eb49eacbfff95",
            "modified_time": "2026-04-07T14:24:50Z",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-04-07T14:39:25.207675892Z",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / pro-express

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pro-express/MAL-2026-2445.json"