chiprook
← Security
SecurityOctober 5, 2026, 15:49

Six Angular typosquats with postinstall hook pulled from npm

On 5 October GitHub's Advisory Database flagged six npm packages as malware, their scoped names one edit away from @angular/core and @angular/cli. All declared version 22.2.1 and carried a postinstall hook piping a script from gitflic.ru through a web.archive.org proxy. All six have been removed from npm.

Six Angular typosquats with postinstall hook pulled from npm
#Angular#Npm#GitHub
Read next
Security

Tetragon in AWS CodeBuild blocks npm postinstall network access

Security

Denylist let 46 of 75 prompt injections through, CapScope only 3

Security

ChainVeil attack hides malware in vite.config.js via forged merge commit

Security

npm Trusted Publishing Abused to Ship GHAPPIER Loader