internallib_v907@1.0.3
Malicious code in internallib_v907 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The package index.js exports a command() function that executes a reverse shell download cradle via child_process.exec: it runs curl against reverse-shell.sh with the IP 10[.]0[.]67[.]6 on port 4444 and pipes the result to sh. The package also ships a .gitlab-ci.yml that runs npm update against a local registry (hxxp://0[.]0[.]0[.]0:4873/) and then executes check.js, which requires the package and calls command(), triggering the reverse shell on CI execution.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 09:29 PM
- analyzed
- Jul 15, 2026, 09:29 PM
Related advisories
- telemetry-metrics@0.2.1
- metrics-ui@99.9.1
- react-hook-scripts@5.4.2
- code-formatter-setup@1.0.0
- ai-pro-sdk@2.0.3
- react-hook-doms@5.3.1
- assertion-utils-js@2.4.3
- @risaoffc/baileys@8.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.