@angulaar/core@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17537
Ecosystem
npm
Summary
The package's package.json defines a postinstall lifecycle script that fetches a JavaScript file from a non-publisher host (gitflic.ru, proxied via web.archive.org, at the path /project/hellscripter/install-scripts/blob/raw?file=node.js) and pipes the response directly into node, executing arbitrary remote code on the installer's machine during npm install. The fetched code is unpinned, unverified, and controlled by a third-party account unrelated to the Angular project. The package name @angulaar/core resembles @angular/core, increasing the likelihood of accidental installation.
Source: amazon-inspector (42861c7641349d2f58380e4f81b13ad9738dd254f224e9f7f239d9cf940cf792)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.