Logo
npm

internallib_v875@1.0.1

Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC

Malicious

OSV ID

MAL-2026-17635

Ecosystem

npm

Summary

internallib_v875 ships an index.js whose exported command() function invokes /bin/bash -c with curl piped to sh, fetching a reverse-shell payload from https://reverse-shell.sh targeted at the hardcoded endpoint 10.0.19.80:8443. Any consumer that requires this package and calls the exported function triggers a fetch-and-execute of attacker-controlled shell content, giving whoever controls that IP:port an interactive shell on the host. The destination is unrelated to any legitimate publisher, the fetched bytes are executed without verification, and the package has no other functionality consistent with its name.

Source: amazon-inspector (a5772f4d8bb3df24cbd5859edef78f7770d547d4c366626552cd2dda539f1440)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.