npm · Malicious package advisory
Malwareinternallib_v275
MAL-2026-17510
Malicious code in internallib_v275 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (80c1c6d383b3defb01da235e39e08ce56276d887e63d900aea2ee689836f71b4) index.js exports a `command` function that invokes `/bin/bash -c` to curl a reverse-shell payload from reverse-shell.sh targeting the hardcoded host 10.0.49.106:443 and pipes the response to `sh`, yielding interactive remote shell access on the installer host whenever the exported API is called. The fetch-and-execute path has no pinning, no hash verification, and runs over an unauthenticated network retrieval. package.json also declares a self-referential dependency on `internallib_v275@^1.0.0`, a dependency-confusion shape consistent with a package targeting an internal registry namespace so that resolution against the public registry pulls this backdoor into internal builds.
Compromised versions (1)
- 1.0.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.