LWA-2026-4399 MAL-2026-5694 ↗ confirmed malware

internallib_v856@99.0.0

Malicious code in internallib_v856 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package internallib_v856@99.0.0 is a dependency-confusion backdoor targeting internal development pipelines. It was published at version 99.0.0 with a name and "Internal lib for testing" description that mimic a private/internal package, and ships a .gitlab-ci.yml configured to install from a local Verdaccio registry (0[.]0[.]0[.]0:4873) and run check.js, which requires the package and invokes its command() function. The command() function in index.js calls child_process.exec to download and execute a shell script from hxxp://10[.]0[.]0[.]145:8080/shell[.]sh via both curl|bash and wget|bash, logging "VERT16X_PWNED" — a clear second-stage remote shell payload delivered into the CI/CD pipeline or developer environment that imports the package.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 07:56 PM
analyzed
Jun 11, 2026, 07:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.