Logo
npm

internallib_v275@1.0.3

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17510

Ecosystem

npm

Summary

index.js exports a command function that invokes /bin/bash -c to curl a reverse-shell payload from reverse-shell.sh targeting the hardcoded host 10.0.49.106:443 and pipes the response to sh, yielding interactive remote shell access on the installer host whenever the exported API is called. The fetch-and-execute path has no pinning, no hash verification, and runs over an unauthenticated network retrieval. package.json also declares a self-referential dependency on internallib_v275@^1.0.0, a dependency-confusion shape consistent with a package targeting an internal registry namespace so that resolution against the public registry pulls this backdoor into internal builds.

Source: amazon-inspector (80c1c6d383b3defb01da235e39e08ce56276d887e63d900aea2ee689836f71b4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.