{"id":"MAL-2026-17537","summary":"Malicious code in @angulaar/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (42861c7641349d2f58380e4f81b13ad9738dd254f224e9f7f239d9cf940cf792)\nThe package's package.json defines a postinstall lifecycle script that fetches a JavaScript file from a non-publisher host (gitflic.ru, proxied via web.archive.org, at the path /project/hellscripter/install-scripts/blob/raw?file=node.js) and pipes the response directly into node, executing arbitrary remote code on the installer's machine during npm install. The fetched code is unpinned, unverified, and controlled by a third-party account unrelated to the Angular project. The package name @angulaar/core resembles @angular/core, increasing the likelihood of accidental installation.\n","modified":"2026-10-05T04:15:06.410838909Z","published":"2026-10-05T03:33:04Z","database_specific":{"malicious-packages-origins":[{"versions":["22.2.1"],"id":"IN-MAL-2026-020998","import_time":"2026-10-05T03:57:37.679348057Z","modified_time":"2026-10-05T03:33:04Z","sha256":"42861c7641349d2f58380e4f81b13ad9738dd254f224e9f7f239d9cf940cf792","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@angulaar/core/v/22.2.1"}],"affected":[{"package":{"name":"@angulaar/core","ecosystem":"npm","purl":"pkg:npm/%40angulaar/core"},"versions":["22.2.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"core-22.2.1.tgz","hashes":{"sha512_sri":"sha512-sZDCtE0Bu6s9Ph81aGhKaAFGNwBfdOutn/bdhPO7YzDt7P8tqBlDI+BsmrLvoXaLsFZcWwC2rnXsSYlZfFQXAg==","sha1":"20d4587e9daacd6f7b1796900d06188264808096"}}],"evidence_files":[{"path":"package.json","sha256":"0f014d3468da11afe86e176fb11fe21a8082cd15768e941cd21c5aee5470258a","tlsh":"aa513624e4f48d6323de6294dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulaar/core/MAL-2026-17537.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}