LWA-2026-4449 MAL-2026-5678 ↗ confirmed malware

internallib_v557@1.0.5

Malicious code in internallib_v557 (npm)

T1059.007 · JavaScriptT1098.004 · SSH Authorized KeysT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1087 · Account DiscoveryT1083 · File and Directory Discovery

Analysis

Package internallib_v557@1.0.5 exports a command() function that, when called, deploys an SSH RSA public key into /home/gitlab-runner/.ssh/authorized_keys (persistent backdoor), reads CTF flag files (/home/internal/user.txt, /root/root.txt) and GitLab CI .git/config credentials from multiple paths, and runs system recon (ls /home/, cat /etc/passwd). The package has no lifecycle hooks, so it does not auto-execute on install, but as a library dependency it is a trojan: any package that requires() and calls .command() is compromised. Minimal package.json with no description, no repository, and a throwaway Gmail publisher (raptor_rex/[account]) — no indication of legitimate use.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 09:25 PM
analyzed
Jun 11, 2026, 09:25 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.