Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @angular_devkit/core (npm)

Version 99.1.1 of @angular_devkit/core (npm) was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Developers and projects using @angular_devkit/core version 99.1.1
Ecosystems
Attack vectors
Affected entities
  • @angular_devkit/core · 99.1.1

The OpenSSF Package Analysis project identified @angular_devkit/core version 99.1.1 on npm as containing malicious code. The malicious package was detected through automated analysis that identified suspicious network communications and command execution patterns.\n\nAccording to the advisory, the compromised version exhibits two key indicators of malicious activity: communication with a domain associated with known malicious activity, and execution of commands consistent with malicious behavior. The package was cataloged in the OpenSSF's malicious packages repository with identifier MAL-2025-6869.\n\nDevelopers who installed version 99.1.1 of @angular_devkit/core should immediately remove or update the package. The legitimate Angular DevKit package should be obtained from the official npm registry after verification.

Indicators of compromise

Packages
  • @angular_devkit/core@99.1.1

Remediation

  • Immediately uninstall @angular_devkit/core version 99.1.1 from all affected projects
  • Update to a known-safe version of @angular_devkit/core from the official npm registry
  • Review project dependencies and lock files to identify all installations of the malicious version
  • Audit systems where the malicious package was installed for signs of compromise
  • Consider rotating credentials and secrets that may have been exposed to systems running the malicious package

Sources

  1. GitHub Advisory GHSA-vr8j-6g9x-548m · GitHub Advisory Database

Cite this entry

"Malicious code in @angular_devkit/core (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-angular-devkit-core-npm-1qgdwy

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in @aligntech-cw/alignerfit (npm)

    Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.

    npmCompromised package
  2. resolvedcritical

    Malicious code in @akunsansan0/susu10 (npm)

    @akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  3. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in @akunsansan0/susu11 (npm)

    @akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.

    npmCompromised package