The Malware Advisory That Flagged Angular’s Real MCP Dependency as the Attack
MAL-2026-17536, published to OSV at 03:31 UTC on 5 October 2026, flags the npm package @angulaar/cli as malware. The package is a typosquat — the doubled “a” is one keystroke from @angular/cli, and it ships the real Angular CLI’s source, README and Google LLC license headers verbatim. That part is not in dispute.
The reasoning the advisory gives for calling it malicious is wrong. Here is the claim, from the OSV record:
“The manifest’s dependencies list has been altered from the upstream package: real @angular/cli depends on ‘@modelcontextprotocol/sdk’, while this package declares ‘@modelcontextprotocol/server’: ‘2.0.0’ … ‘@modelcontextprotocol/server’ is not the official MCP package name, so npm install resolves and installs whatever bytes are published under that attacker-chosen name/version.”
Two checkable assertions sit in there. We checked both against the npm registry.
Assertion one: the real @angular/cli depends on @modelcontextprotocol/sdk
It does not. We pulled the manifest for @angular/cli at version 22.2.1 — the current release, published 1 October 2026, and the exact version the typosquat mirrors. Its dependency is:
"@modelcontextprotocol/server": "2.0.0"
Identical to the string the advisory calls an attacker alteration. The “altered manifest” matches upstream byte for byte on the one field the advisory builds its case on.
The confusion has a traceable origin. Walking the @angular/cli release history shows a clean split down the two maintained lines:
20.3.37,20.3.38,21.2.23,21.2.24,21.2.25,22.1.7,22.1.8,22.1.9→@modelcontextprotocol/sdk 1.30.022.2.0-next.6(2 September 2026) onward, through22.2.0,22.2.1and22.3.0-next.0→@modelcontextprotocol/server
The switch landed in the 22.2 prerelease line in early September and shipped to stable with 22.2.0 on 23 September. A detector whose baseline for “what @angular/cli depends on” was built from the 20.x/21.x/22.1 maintenance branches — still actively published, as recently as 5 October — would see the 22.2 manifest as modified. It is modified, relative to that baseline. It was modified by Angular.
Assertion two: @modelcontextprotocol/server is not an official MCP package name
It is. We queried the registry entry directly. @modelcontextprotocol/server was first published on 1 April 2026, is at version 2.3.0 across 13 published versions, lists its author as Anthropic, PBC, points its repository at github.com/modelcontextprotocol/typescript-sdk, its homepage at modelcontextprotocol.io, and carries the same maintainer accounts as @modelcontextprotocol/sdk itself.
It is not a squat on the MCP scope. It is the MCP TypeScript SDK’s v2 server package. The SDK was broken into scoped components — the project’s 2 October 2026 release batch tagged @modelcontextprotocol/server, client, core, node, express, hono, fastify, codemod and server-legacy together at matching versions. @modelcontextprotocol/sdk 1.x continues in parallel at 1.32.0. Both are real, both are Anthropic-published, and a tool that knows only the older name will misread the newer one as an impostor.
Why this matters more than one bad advisory
The conclusion — this package is malicious — happens to be right. @angulaar/cli is a one-character typosquat shipping cloned source under a scope its publisher does not own, and it belongs in the fourteen-package Angular squatting wave it was published alongside. Removing it was correct.
But the evidence offered for that conclusion is the opposite of the truth, and that has costs that outlast this one record:
- The indicator propagates. Advisory text flows from OSV into GitHub Advisory Database, vendor scanners, SBOM tooling, and the blog posts and dashboards that paraphrase them. A sentence asserting that
@modelcontextprotocol/serveris “not the official MCP package name” is now a quotable, machine-readable claim about a legitimate Anthropic package that tens of thousands of projects will pull in as MCP SDK v2 adoption grows. - The false-positive direction is the dangerous one. The same logic that flagged Angular’s real dependency as attacker-chosen will flag every project that migrates to SDK v2. Teams that learn their scanner cries malware on routine upstream renames start discounting the scanner — and the next alert is the fetch-and-pipe one.
- Renames are a permanent blind spot for baseline-diffing detectors. Package splits, scope migrations and major-version reorganisations are normal ecosystem events. A detector that treats “dependency name differs from my cached baseline” as evidence of substitution will misfire on every one of them, and will do so most often on the fast-moving AI tooling where the renames are happening now.
- The real signal was sitting right there. The scope name is not owned by the Angular team, the source is copied wholesale, and thirteen sibling packages published in the same hours carry an explicit
curl | nodepayload. None of that required a manifest-diff theory.
What to do
- Do not remove
@modelcontextprotocol/serverfrom your tree on the strength of this advisory. Verify publisher, repository and maintainer set against the registry yourself — it checks out as the official SDK v2 server package. - When a scanner flags a dependency name rather than behaviour, verify upstream before acting. One registry lookup of the genuine package’s current manifest distinguishes an attacker substitution from an upstream rename. That lookup is cheap and it is the whole check.
- Weight behavioural indicators above manifest-diff indicators. Install-time network fetches, piped interpreters, lifecycle hooks and unpinned remote sources are facts about what the code does. A dependency-name delta is a fact about your baseline.
- Expect more of this as MCP tooling churns. The SDK v1-to-v2 split is exactly the kind of event that generates these errors, and MCP packages sit in the dependency trees of agent harnesses that scanners already treat with suspicion. We have tracked the genuine October MCP SDK advisories and the gaps in how they reach npm audit; this is the same pipeline failing in the other direction.
Verification note: we read the full OSV record for MAL-2026-17536 and quote its reasoning directly. We queried the npm registry API for the @angular/cli manifest at version 22.2.1 and across its recent release history, and for the registry entries of @modelcontextprotocol/server and @modelcontextprotocol/sdk, taking versions, dependency fields, publication dates, author, repository, homepage and maintainer lists from those responses. We read the modelcontextprotocol/typescript-sdk release list via the GitHub API for the 2 October 2026 scoped-package batch. We did not install or execute @angulaar/cli, and we do not dispute that it is a typosquat or that its removal was appropriate — our finding concerns the advisory’s stated rationale, not its verdict. We did not contact Amazon Inspector or OSV before publication.
Sources:
- OSV — MAL-2026-17536, malicious code in @angulaar/cli (5 October 2026; the dependency-substitution rationale quoted above)
- npm registry — @angular/cli 22.2.1 manifest, showing the @modelcontextprotocol/server 2.0.0 dependency
- npm — @modelcontextprotocol/server, published by Anthropic, PBC from the MCP TypeScript SDK repository
- modelcontextprotocol/typescript-sdk — releases, including the 2 October 2026 scoped v2 package batch