{"id":"MAL-2026-17562","summary":"Malicious code in internallib_v923 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2d02d4c28dbcb2db331a6da7dba2476e3b7daf4f4d53d51d76d79ad4732d28a4)\nindex.js exports a command() function that shells out via /bin/bash -c to curl a payload from reverse-shell.sh and pipe it to sh, yielding a reverse shell to the hardcoded callback host 10.0.72.151:443. Any consumer requiring the package and invoking the exported API triggers remote-fetched shell execution with full-host control by the operator of the hardcoded callback. The manifest also declares a single dependency internallib_v79 and the sibling check.js invokes require('internallib_v79').command(), indicating the same payload shape is distributed across a package family with dependency-confusion-style naming (internallib_v\u003cn\u003e).\n","modified":"2026-10-05T04:15:05.323040167Z","published":"2026-10-05T03:31:57Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-05T03:31:57Z","sha256":"2d02d4c28dbcb2db331a6da7dba2476e3b7daf4f4d53d51d76d79ad4732d28a4","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-020991","import_time":"2026-10-05T03:57:37.149785186Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/internallib_v923/v/1.0.3"}],"affected":[{"package":{"name":"internallib_v923","ecosystem":"npm","purl":"pkg:npm/internallib_v923"},"versions":["1.0.3"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"d6d77ace8ee208ea18e1415a9ea9cccbd69bf15bb4c88fc2a032c063cc55b8a0","tlsh":"bcd022a789a6163abb4822e09c02f5a2a8578c202b2804b0a0804051088285da34b0ee"},{"path":"package.json","sha256":"d87ba0bb1ceb081196c3d3d01f07551df168f6dffd12b62c6dfea02b0b10ff38","tlsh":"1ed05e3059625d7321d5136a2c6a845372a1ce2f5096bc0957cb5d2c41dfab398fd35c"}],"package_integrity":[{"filename":"internallib_v923-1.0.3.tgz","hashes":{"sha1":"6d4e1b9ed145f4579928c52b3a1b033423616df8","sha512_sri":"sha512-uqFhaGd0J5mp4h7q5xY8YMnbwuCDOmXGBbu9t1Nid602pdzZl7DNljVoQBeJl6EuH9jfg6czBS6tgq/n4hp3mQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/internallib_v923/MAL-2026-17562.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}