Six Angular typosquats, one postinstall hook, published the same morning
On 5 October 2026 — this morning — GitHub's Advisory Database reviewed six npm packages as malware, all scoped names one edit away from @angular/core or @angular/cli : @angupar/core , @anngular/core , @abgular/core , @anfular/core , @anguar/core and @angulaar/cli . Every one of them declared version 22.2.1 — which, as of today, is the real, current version of @angular/core on npm. That is a…
On October 5, 2026, GitHub's Advisory Database identified six npm packages with typosquatted names, all one edit away from the official @angular/core or @angular/cli packages. Each of the six packages claimed to be version 22.2.1, the same current version of @angular/core on npm. This is a change from a previous campaign in September, where four PyPI typosquats claimed slightly older version numbers.
Five of the packages used a postinstall hook to execute an unpinned, unverified script during npm install, while the sixth package ( @angulaar/cli) declared a dependency on a different swapped package. GitHub removed all six packages, but their metadata still showed up in the registry for a brief period before being unpublished.
Real @angular/core, published in 2016, had over 7.2 million downloads in the week ending October 3, 2026, while the fake packages did not appear in npm's download statistics.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.