Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17632 confirms this npm version as malicious. index.js line 5 exports a function that invokes /bin/bash to curl https://reverse-shell.sh/10.0.19.80:4443 and pipe the response to a shell, delivering an interactive reverse shell to the hardcoded endpoint 10.0.19.80:4443 on the host where the exported function is called...
This report applies to internallib_v23@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.