npm

internallib_v392 @2.0.3

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 3:27 AM UTC

Malicious

OSV ID

MAL-2026-13924

Ecosystem

npm

Summary

index.js exports a function that invokes /bin/bash -c to curl a remote reverse-shell script from reverse-shell.sh and pipe it to sh, targeting the hardcoded IP 10.0.72.234 on port 443. When the exported API is called by a consumer, the installer's host fetches and executes attacker-controlled shell code, granting the attacker at 10.0.72.234:443 a reverse shell on the installer's machine. The package metadata is minimal (empty description/author) and the package name has a typosquat-like shape, consistent with a malicious drop rather than a legitimate library.

Source: amazon-inspector (29fa6db9e4a601df500639714e53f29cde2413c54a6ec31ea6bf38fbb0aabd2f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.