LWA-2026-6318 MAL-2026-6796 ↗ confirmed malware

internallib_v234@1.0.3

Malicious code in internallib_v234 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package index.js exports a function that executes a reverse shell via child_process.exec: it curls a script from reverse-shell.sh/10[.]0[.]74[.]133:443 and pipes it to sh. The package declares a self-dependency (internallib_v234@^1.0.0) and ships a .gitlab-ci.yml that triggers the payload in CI pipelines by running npm update against a local registry (hxxp://0[.]0[.]0[.]0:4873/) then executing check.js which requires the package and invokes the command. The reverse shell connects to 10[.]0[.]74[.]133:443.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 03:57 PM
analyzed
Jul 4, 2026, 03:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.