npm package intelligence

expresss — deep security report

ShadowCanopy's full breakdown of expresss on npm: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Dangerous — blocked
This package failed ShadowCanopy's checks and is blocked by default across every project.
Scanned 8/7/2026
Rejectedexpresss@0.0.0View on registry ↗latest: 0.0.0

Package name 'expresss' is a clear typosquat of the popular 'express' package (one character edit), with no other functionality present. This matches the definition of malicious typosquatting to deceive users.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

Package named "expresss" (version 0.0.0) described as a "temp test" with no dependencies. Main entry point is index.js; only script is a test that reports no tests specified.

Capabilities

  • Defines a test script that exits with error

Data access

  • None observed

Network

  • No network access observed

Name triggers a typosquatting indicator relative to the popular "express" package, though manifest shows no executable behavior beyond a placeholder test script.

Why this is dangerous

Package name 'expresss' is a typosquatted variant of the popular 'express' package.

The package.json declares the name 'expresss', a common typosquatting attack targeting the widely-used 'express' framework. No other code is present in the flagged files, but the name alone is a strong indicator of intent to deceive users into installing a malicious or fake package.

Typosquatted package namepackage.json:2-2

What: Declares package name as "expresss" instead of "express".

Why: This is a classic typosquatting technique to impersonate the legitimate express package and trick developers into installing the wrong module.

Security findings (1)

Static analysis rule matches, with the exact code that triggered them.

highTyposquatting indicatorATK-006package.json

Name "expresss" is one edit away from popular package "express"

Package metadata

LicenseISC

temp test

Files in package (2)

package.jsonpackage/package.json

How ShadowCanopy checks npm packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/expresss