Six Angular typosquats, one postinstall hook, published the same morning
This story is from 2026-10-05. It is preserved in the archive; the latest stories are on the live feed.
On 5 October 2026 — this morning — GitHub's Advisory Database reviewed six npm packages as malware, all scoped names one edit away from @angular/core or @angular/cli : @angupar/core , @anngular/core , @abgular/core , @anfular/core , @anguar/core and @angulaar/cli . Every one of them declared versio…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-10-05 08:49 · DEV Community — AI
Six Angular typosquats, one postinstall hook, published the same morning