Malicious Package in angluar-cli
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Sep 11, 2020 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
Description
        Reviewed
      Aug 31, 2020 
    
  
        Published to the GitHub Advisory Database
      Sep 11, 2020 
    
  
        Last updated
      Jan 9, 2023 
    
  
Version 0.0.3 of
angluar-clicontains malicious code as a postinstall script. The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. When installed the package attempts to remove files and stop processes related to McAfee antivirus on macOS.Recommendation
Remove the package from your environment and verify whether files were deleted and if processes were stopped.
References