internallib_v23@1.0.1
Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC
OSV ID
MAL-2026-17632
Ecosystem
npm
Summary
index.js line 5 exports a function that invokes /bin/bash to curl https://reverse-shell.sh/10.0.19.80:4443 and pipe the response to a shell, delivering an interactive reverse shell to the hardcoded endpoint 10.0.19.80:4443 on the host where the exported function is called. The destination is a hardcoded private-range IP, there is no authentication, no documentation of the behavior, and the fetched content is executed directly. The package's only exported functionality is this backdoor dropper.
Source: amazon-inspector (bf294381eb4f87a0dcccbd00977ac38ab25a8108639c8cc08543c7d0e09b5f36)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.