• Sources: analysis, HN submission
  • Summary: The npm user dirtyblanket published nine packages on 2026-09-29 between 06:05 and 06:38 UTC, eight impersonating Express and one React. The analysis names them as xeprews 5.2.1, express-javascript 5.2.1, express-nodejs 5.2.1, react-nodejs 19.3.0, exprdd 5.2.1, exprrdd 5.2.1, exptrdd 5.2.1, exptred 5.2.1, and exptredd 5.2.1. A preinstall hook fetches a loader through the Internet Archive Wayback Machine, a domain many allowlists trust, and that loader pulls a 227-line bash worm from Codeberg that installs the CHAOS remote access tool on Linux as a fake systemd font service reachable over Tor, then makes the binary and unit files immutable with chattr +i. It spreads three ways: it uses every OpenSSH private key on the machine to log in to hosts listed in known_hosts and run itself there, it appends an install line to the AUR packages those keys can push so every user upgrading them runs the worm, and it uses local npm tokens to publish new versions of the machine's own packages carrying the same preinstall hook.
  • Why it matters: Anyone who installed one of these packages on Linux should treat that machine and every key and token reachable from it as compromised, and the loader is unpinned so its contents can change at any time.
  • Follow-up: Track whether the affected AUR packages are cleaned, and whether any downstream npm publish carried the preinstall hook forward to packages that were not part of the original nine.

send feedback on this story