npm · Malicious package advisory
Malwareinternallib_v275
GHSA-wp69-7q5m-655v
Malicious code in internallib_v275 (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.3` ## Source: amazon-inspector (80c1c6d383b3defb01da235e39e08ce56276d887e63d900aea2ee689836f71b4) index.js exports a `command` function that invokes `/bin/bash -c` to curl a reverse-shell payload from reverse-shell.sh targeting the hardcoded host 10.0.49.106:443 and pipes the response to `sh`, yielding interactive remote shell access on the installer host whenever the exported API is called. The fetch-and-execute path has no pinning, no hash verification, and runs over an unauthenticated network retrieval. package.json also declares a self-referential dependency on `internallib_v275@^1.0.0`, a dependency-confusion shape consistent with a package targeting an internal registry namespace so that resolution against the public registry pulls this backdoor into internal builds. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/internallib_v275/MAL-2026-17510.json)) **References:** - https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/internallib_v275/MAL-2026-17510.json - https://www.npmjs.com/package/internallib_v275/v/1.0.3 - https://github.com/advisories/GHSA-wp69-7q5m-655v
Compromised versions (1)
- = 1.0.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.