internallib_v856@99.0.0
Malicious code in internallib_v856 (npm)
Analysis
Package internallib_v856@99.0.0 is a dependency-confusion backdoor targeting internal development pipelines. It was published at version 99.0.0 with a name and "Internal lib for testing" description that mimic a private/internal package, and ships a .gitlab-ci.yml configured to install from a local Verdaccio registry (0[.]0[.]0[.]0:4873) and run check.js, which requires the package and invokes its command() function. The command() function in index.js calls child_process.exec to download and execute a shell script from hxxp://10[.]0[.]0[.]145:8080/shell[.]sh via both curl|bash and wget|bash, logging "VERT16X_PWNED" — a clear second-stage remote shell payload delivered into the CI/CD pipeline or developer environment that imports the package.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 07:56 PM
- analyzed
- Jun 11, 2026, 07:57 PM
Related advisories
- chalk-plus-ts@1.0.3
- ecto-rust-read-f3a9c1@1.0.2
- noon-contracts@1.0.0
- node-env-resolver-vite@2.4.2
- pocteszep@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- miro-plugin-tag-crawler@1.0.0
- yelp-react-component-chaos@8.14.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.