internallib_v234@1.0.3
Malicious code in internallib_v234 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Package index.js exports a function that executes a reverse shell via child_process.exec: it curls a script from reverse-shell.sh/10[.]0[.]74[.]133:443 and pipes it to sh. The package declares a self-dependency (internallib_v234@^1.0.0) and ships a .gitlab-ci.yml that triggers the payload in CI pipelines by running npm update against a local registry (hxxp://0[.]0[.]0[.]0:4873/) then executing check.js which requires the package and invokes the command. The reverse shell connects to 10[.]0[.]74[.]133:443.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 03:57 PM
- analyzed
- Jul 4, 2026, 03:58 PM
Related advisories
- polytrade@2.4.1
- @bobfrankston/mailx-store@0.1.58
- chai-presentation@0.0.3
- chai-presentation@0.0.2
- chai-presentation@0.0.1
- chai-as-serialized@7.0.8
- chai-redirection@0.0.1
- react-icons-svgo@1.5.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.