The published command() export downloads a reverse-shell script from reverse-shell.sh and executes it with bash. check.js and GitLab CI call that function after install.
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe main module exports a command function that runs bash to curl https://reverse-shell.sh/10.0.16.19:443 and pipe it into sh.
index.jsView on unpkg · L1package.json sets main to index.js and adds a runtime dependency on internallib_v949 itself.
package.jsonView on unpkg · L5check.js requires internallib_v949 and immediately calls command(), which is the reverse-shell entry.
check.jsView on unpkg · L1GitLab CI installs from a local registry and then runs node check.js, so that function is the exercised path.
.gitlab-ci.ymlView on unpkg · L22This report applies to internallib_v949@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe main module exports a command function that runs bash to curl https://reverse-shell.sh/10.0.16.19:443 and pipe it into sh.
index.jsView on unpkg · L1package.json sets main to index.js and adds a runtime dependency on internallib_v949 itself.
package.jsonView on unpkg · L5check.js requires internallib_v949 and immediately calls command(), which is the reverse-shell entry.
check.jsView on unpkg · L1GitLab CI installs from a local registry and then runs node check.js, so that function is the exercised path.
.gitlab-ci.ymlView on unpkg · L22