Logo
npm

@angulaar/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17537

Ecosystem

npm

Summary

The package's package.json defines a postinstall lifecycle script that fetches a JavaScript file from a non-publisher host (gitflic.ru, proxied via web.archive.org, at the path /project/hellscripter/install-scripts/blob/raw?file=node.js) and pipes the response directly into node, executing arbitrary remote code on the installer's machine during npm install. The fetched code is unpinned, unverified, and controlled by a third-party account unrelated to the Angular project. The package name @angulaar/core resembles @angular/core, increasing the likelihood of accidental installation.

Source: amazon-inspector (42861c7641349d2f58380e4f81b13ad9738dd254f224e9f7f239d9cf940cf792)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.