Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in internallib_v164 (npm)

0
Critical
Published: 08/11/2026 (08/11/2026, 22:21:24 UTC)
Source: GCVE Database
Product: internallib_v164

Description

The internallib_v164 npm package contains malicious code that executes a reverse shell command upon invocation. This command fetches and runs a script from a remote server, opening an interactive shell to a hardcoded internal network address. This behavior grants an attacker arbitrary code execution and persistent access on the host machine. The affected package versions include 6.0.9, 4.0.9, 1.0.7, and 1.0.9. Removal of the package alone may not fully remediate the compromise, as the attacker may have already established persistent control. Immediate secret and key rotation from a different, uncompromised system is strongly advised.

Affected software

npmghsa
internallib_v164
Affected versions
=6.0.9=4.0.9=1.0.7=1.0.9

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:58:47 UTC

Technical Analysis

The internallib_v164 npm package exports a function that runs a shell command executing a curl request to a remote server (reverse-shell.sh) at the IP 10.0.72.234:4444, piping the downloaded script to sh. This results in an outbound interactive reverse shell connection to the attacker-controlled internal network address, enabling arbitrary code execution and persistent interactive access on the compromised host. The malicious behavior is triggered when the exported function is invoked by a consumer of the package. The affected versions are explicitly 6.0.9, 4.0.9, 1.0.7, and 1.0.9. Due to the nature of the compromise, full system control by an attacker is likely, and simple removal of the package does not guarantee full remediation.

Potential Impact

Hosts with the affected internallib_v164 package versions installed and invoked are fully compromised, as the package opens a reverse shell to an attacker-controlled internal network address. This grants the attacker arbitrary code execution and persistent interactive access, potentially exposing all secrets and keys stored on the host. The compromise is severe and may allow lateral movement within internal networks. Removal of the package alone is insufficient to ensure system integrity.

Mitigation Recommendations

No official patch or fix is indicated in the available data. Immediate removal of the internallib_v164 package versions 6.0.9, 4.0.9, 1.0.7, and 1.0.9 is recommended. However, because the package grants full control to an attacker, it is critical to assume full system compromise. All secrets and keys stored on the affected host should be rotated immediately from a separate, uncompromised system. Comprehensive incident response and forensic analysis should be conducted to identify and remove any additional malicious artifacts or persistence mechanisms.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13764
Osv Schema Version
1.7.4
Aliases
["GHSA-3qvf-g7pq-m3m3"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b4dbf8831d539cdd741

Added to database: 08/12/2026, 16:11:57 UTC

Last enriched: 08/12/2026, 16:58:47 UTC

Last updated: 08/12/2026, 16:58:47 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses