Logo
npm

internallib_v23@1.0.1

Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC

Malicious

OSV ID

MAL-2026-17632

Ecosystem

npm

Summary

index.js line 5 exports a function that invokes /bin/bash to curl https://reverse-shell.sh/10.0.19.80:4443 and pipe the response to a shell, delivering an interactive reverse shell to the hardcoded endpoint 10.0.19.80:4443 on the host where the exported function is called. The destination is a hardcoded private-range IP, there is no authentication, no documentation of the behavior, and the fetched content is executed directly. The package's only exported functionality is this backdoor dropper.

Source: amazon-inspector (bf294381eb4f87a0dcccbd00977ac38ab25a8108639c8cc08543c7d0e09b5f36)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.