Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-04 · updated: 2026-10-04 · tags: [incident, global, supply-chain] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: false

The supply-chain watch this window verified a fresh cluster of malicious npm packages typosquatting prominent open-source libraries — including @angulra/core, @angularr/core and @nagular/core — along with imitations of the Bitwarden password-manager library. These packaging-spelling lookalikes (a single transposed character separating them from the genuine Angular Core package, which has millions of weekly downloads) are a classic vector for developer dependency-confusion: a mistyped or copy-pasted npm install silently pulls attacker-controlled code into a build. The records are confirmed malicious assets in the OpenSourceMalware archive, not raw signals, and are typically used to deliver infostealers or backdoors into downstream applications. Organisations should audit dependency graphs against the affected names, enable strict package-name resolution, and treat transitive typosquat pressure as a standing supply-chain control rather than a one-off event.

Attribute Detail
Sector Global (Macro)
Date 2026-10-04
Source OpenSourceMalware — @angulra/core
Reliability Tier 2