LWA-2026-6830 MAL-2026-10691 ↗ confirmed malware

internallib_v907@1.0.3

Malicious code in internallib_v907 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package index.js exports a command() function that executes a reverse shell download cradle via child_process.exec: it runs curl against reverse-shell.sh with the IP 10[.]0[.]67[.]6 on port 4444 and pipes the result to sh. The package also ships a .gitlab-ci.yml that runs npm update against a local registry (hxxp://0[.]0[.]0[.]0:4873/) and then executes check.js, which requires the package and calls command(), triggering the reverse shell on CI execution.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 09:29 PM
analyzed
Jul 15, 2026, 09:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.