Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-05 · updated: 2026-10-05 · tags: [incident, global, supply-chain] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

The supply-chain watch's 5 October batch of human-verified malicious assets shows a coordinated typosquat campaign against the Angular framework's core package: twelve lookalike scopes (@qngular/core, @anuglar/core, @anngular/core, @angupar/core, @angulr/core, @angulaar/core, @anguar/core, @angjlar/core, @anfular/core, @abgular/core — all version 22.2.1 — plus @angulra/core and @angularr/core at 1.0.67). Each declares a preinstall or postinstall hook that curls a second-stage script from gitflic.ru — proxied through web.archive.org to hide the attacker domain — and pipes it straight into node, giving arbitrary code execution at install time. The batch also surfaced @inpeek/odata (99.99.99, install-time exfiltration to a webhook.site collector), hardhat-spack (3.0.2, fetches a base64-hidden vercel.app URL and executes it via new Function), and the a11y-tabindex-manager / dom-focus-sentinel pair, whose shared thunderboltRegistry.js runs host-reconnaissance shell commands on module load and exfiltrates the output (OSV advisories MAL-2026-17501 and MAL-2026-17503). Any of these in a lockfile is an incident.

Attribute Detail
Sector Global (Macro)
Date 2026-10-05
Source OpenSourceMalware — @qngular/core
Reliability Tier 2