-= Per source details. Do not edit below this line.=-
index.js exports a command() function that shells out via /bin/bash -c to curl a payload from reverse-shell.sh and pipe it to sh, yielding a reverse shell to the hardcoded callback host 10.0.72.151:443. Any consumer requiring the package and invoking the exported API triggers remote-fetched shell execution with full-host control by the operator of the hardcoded callback. The manifest also declares a single dependency internallib_v79 and the sibling check.js invokes require('internallib_v79').command(), indicating the same payload shape is distributed across a package family with dependency-confusion-style naming (internallib_v).
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020991",
"import_time": "2026-10-05T03:57:37.149785186Z",
"modified_time": "2026-10-05T03:31:57Z",
"sha256": "2d02d4c28dbcb2db331a6da7dba2476e3b7daf4f4d53d51d76d79ad4732d28a4",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "d6d77ace8ee208ea18e1415a9ea9cccbd69bf15bb4c88fc2a032c063cc55b8a0",
"tlsh": "bcd022a789a6163abb4822e09c02f5a2a8578c202b2804b0a0804051088285da34b0ee"
},
{
"path": "package.json",
"sha256": "d87ba0bb1ceb081196c3d3d01f07551df168f6dffd12b62c6dfea02b0b10ff38",
"tlsh": "1ed05e3059625d7321d5136a2c6a845372a1ce2f5096bc0957cb5d2c41dfab398fd35c"
}
],
"package_integrity": [
{
"filename": "internallib_v923-1.0.3.tgz",
"hashes": {
"sha1": "6d4e1b9ed145f4579928c52b3a1b033423616df8",
"sha512_sri": "sha512-uqFhaGd0J5mp4h7q5xY8YMnbwuCDOmXGBbu9t1Nid602pdzZl7DNljVoQBeJl6EuH9jfg6czBS6tgq/n4hp3mQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/internallib_v923/MAL-2026-17562.json"