Logo
npm

internallib_v923@1.0.3

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17562

Ecosystem

npm

Summary

index.js exports a command() function that shells out via /bin/bash -c to curl a payload from reverse-shell.sh and pipe it to sh, yielding a reverse shell to the hardcoded callback host 10.0.72.151:443. Any consumer requiring the package and invoking the exported API triggers remote-fetched shell execution with full-host control by the operator of the hardcoded callback. The manifest also declares a single dependency internallib_v79 and the sibling check.js invokes require('internallib_v79').command(), indicating the same payload shape is distributed across a package family with dependency-confusion-style naming (internallib_v<n>).

Source: amazon-inspector (2d02d4c28dbcb2db331a6da7dba2476e3b7daf4f4d53d51d76d79ad4732d28a4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.