MAL-2026-17562

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/internallib_v923/MAL-2026-17562.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17562
Published
2026-10-05T03:31:57Z
Modified
2026-10-05T04:15:05Z
Summary
Malicious code in internallib_v923 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (2d02d4c28dbcb2db331a6da7dba2476e3b7daf4f4d53d51d76d79ad4732d28a4)

index.js exports a command() function that shells out via /bin/bash -c to curl a payload from reverse-shell.sh and pipe it to sh, yielding a reverse shell to the hardcoded callback host 10.0.72.151:443. Any consumer requiring the package and invoking the exported API triggers remote-fetched shell execution with full-host control by the operator of the hardcoded callback. The manifest also declares a single dependency internallib_v79 and the sibling check.js invokes require('internallib_v79').command(), indicating the same payload shape is distributed across a package family with dependency-confusion-style naming (internallib_v).

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020991",
            "import_time":  "2026-10-05T03:57:37.149785186Z",
            "modified_time":  "2026-10-05T03:31:57Z",
            "sha256":  "2d02d4c28dbcb2db331a6da7dba2476e3b7daf4f4d53d51d76d79ad4732d28a4",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / internallib_v923

Package

Name
internallib_v923
View open source insights on deps.dev
Purl
pkg:npm/internallib_v923

Affected ranges

Affected versions

1.*
1.0.3

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "d6d77ace8ee208ea18e1415a9ea9cccbd69bf15bb4c88fc2a032c063cc55b8a0",
            "tlsh":  "bcd022a789a6163abb4822e09c02f5a2a8578c202b2804b0a0804051088285da34b0ee"
        },
        {
            "path":  "package.json",
            "sha256":  "d87ba0bb1ceb081196c3d3d01f07551df168f6dffd12b62c6dfea02b0b10ff38",
            "tlsh":  "1ed05e3059625d7321d5136a2c6a845372a1ce2f5096bc0957cb5d2c41dfab398fd35c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "internallib_v923-1.0.3.tgz",
            "hashes":  {
                "sha1":  "6d4e1b9ed145f4579928c52b3a1b033423616df8",
                "sha512_sri":  "sha512-uqFhaGd0J5mp4h7q5xY8YMnbwuCDOmXGBbu9t1Nid602pdzZl7DNljVoQBeJl6EuH9jfg6czBS6tgq/n4hp3mQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/internallib_v923/MAL-2026-17562.json"