Malicious code in internallib_v164 (npm)
The internallib_v164 npm package contains malicious code that executes a reverse shell command upon invocation. This command fetches and runs a script from a remote server, opening an interactive shell to a hardcoded internal network address. This behavior grants an attacker arbitrary code execution and persistent access on the host machine. The affected package versions include 6.0.9, 4.0.9, 1.0.7, and 1.0.9. Removal of the package alone may not fully remediate the compromise, as the attacker may have already established persistent control. Immediate secret and key rotation from a different, uncompromised system is strongly advised.
AI Analysis
Technical Summary
The internallib_v164 npm package exports a function that runs a shell command executing a curl request to a remote server (reverse-shell.sh) at the IP 10.0.72.234:4444, piping the downloaded script to sh. This results in an outbound interactive reverse shell connection to the attacker-controlled internal network address, enabling arbitrary code execution and persistent interactive access on the compromised host. The malicious behavior is triggered when the exported function is invoked by a consumer of the package. The affected versions are explicitly 6.0.9, 4.0.9, 1.0.7, and 1.0.9. Due to the nature of the compromise, full system control by an attacker is likely, and simple removal of the package does not guarantee full remediation.
Potential Impact
Hosts with the affected internallib_v164 package versions installed and invoked are fully compromised, as the package opens a reverse shell to an attacker-controlled internal network address. This grants the attacker arbitrary code execution and persistent interactive access, potentially exposing all secrets and keys stored on the host. The compromise is severe and may allow lateral movement within internal networks. Removal of the package alone is insufficient to ensure system integrity.
Mitigation Recommendations
No official patch or fix is indicated in the available data. Immediate removal of the internallib_v164 package versions 6.0.9, 4.0.9, 1.0.7, and 1.0.9 is recommended. However, because the package grants full control to an attacker, it is critical to assume full system compromise. All secrets and keys stored on the affected host should be rotated immediately from a separate, uncompromised system. Comprehensive incident response and forensic analysis should be conducted to identify and remove any additional malicious artifacts or persistence mechanisms.
Malicious code in internallib_v164 (npm)
Description
The internallib_v164 npm package contains malicious code that executes a reverse shell command upon invocation. This command fetches and runs a script from a remote server, opening an interactive shell to a hardcoded internal network address. This behavior grants an attacker arbitrary code execution and persistent access on the host machine. The affected package versions include 6.0.9, 4.0.9, 1.0.7, and 1.0.9. Removal of the package alone may not fully remediate the compromise, as the attacker may have already established persistent control. Immediate secret and key rotation from a different, uncompromised system is strongly advised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The internallib_v164 npm package exports a function that runs a shell command executing a curl request to a remote server (reverse-shell.sh) at the IP 10.0.72.234:4444, piping the downloaded script to sh. This results in an outbound interactive reverse shell connection to the attacker-controlled internal network address, enabling arbitrary code execution and persistent interactive access on the compromised host. The malicious behavior is triggered when the exported function is invoked by a consumer of the package. The affected versions are explicitly 6.0.9, 4.0.9, 1.0.7, and 1.0.9. Due to the nature of the compromise, full system control by an attacker is likely, and simple removal of the package does not guarantee full remediation.
Potential Impact
Hosts with the affected internallib_v164 package versions installed and invoked are fully compromised, as the package opens a reverse shell to an attacker-controlled internal network address. This grants the attacker arbitrary code execution and persistent interactive access, potentially exposing all secrets and keys stored on the host. The compromise is severe and may allow lateral movement within internal networks. Removal of the package alone is insufficient to ensure system integrity.
Mitigation Recommendations
No official patch or fix is indicated in the available data. Immediate removal of the internallib_v164 package versions 6.0.9, 4.0.9, 1.0.7, and 1.0.9 is recommended. However, because the package grants full control to an attacker, it is critical to assume full system compromise. All secrets and keys stored on the affected host should be rotated immediately from a separate, uncompromised system. Comprehensive incident response and forensic analysis should be conducted to identify and remove any additional malicious artifacts or persistence mechanisms.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13764
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-3qvf-g7pq-m3m3"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b4dbf8831d539cdd741
Added to database: 08/12/2026, 16:11:57 UTC
Last enriched: 08/12/2026, 16:58:47 UTC
Last updated: 08/12/2026, 16:58:47 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.