VYPR

npm · Malicious package advisory

Malware

internallib_v275

MAL-2026-17510

Malicious code in internallib_v275 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (80c1c6d383b3defb01da235e39e08ce56276d887e63d900aea2ee689836f71b4)
index.js exports a `command` function that invokes `/bin/bash -c` to curl a reverse-shell payload from reverse-shell.sh targeting the hardcoded host 10.0.49.106:443 and pipes the response to `sh`, yielding interactive remote shell access on the installer host whenever the exported API is called. The fetch-and-execute path has no pinning, no hash verification, and runs over an unauthenticated network retrieval. package.json also declares a self-referential dependency on `internallib_v275@^1.0.0`, a dependency-confusion shape consistent with a package targeting an internal registry namespace so that resolution against the public registry pulls this backdoor into internal builds.

Compromised versions (1)

  • 1.0.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.