OpenSSF/OSV advisory MAL-2026-17536 confirms this npm version as malicious. Package name '@angulaar/cli' (double 'a') is a one-character edit of '@angular/cli'; README, LICENSE headers, and source files are copied verbatim from the real Angular CLI (Google LLC copyright, angular.dev license URLs, README pointing issues to github.com/angular/angular-cli)...
Package source references dynamic require/import behavior.
bin/bootstrap.jsView on unpkg · L25Package source executes code through a VM context API.
src/command-builder/utilities/schematic-engine-host.jsView on unpkg · L6This report applies to @angulaar/cli@22.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A manifest entrypoint or package-local install chain reaches persistence behavior.
src/utilities/completion.jsView on unpkg · L6Source writes installer persistence such as shell profile or service configuration.
src/utilities/completion.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/ng.jsView on unpkgPackage source references dynamic require/import behavior.
bin/bootstrap.jsView on unpkg · L25Package source executes code through a VM context API.
src/command-builder/utilities/schematic-engine-host.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
src/utilities/completion.jsView on unpkg · L6Source writes installer persistence such as shell profile or service configuration.
src/utilities/completion.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/ng.jsView on unpkg