Malicious code in internallib_v550 (npm)
MAL-2026-16439
Published · Modified
Dependency scanning
Check whether internallib_v550 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (ef32979e04c5e9caca40fb38a9c9ed2b9a75e015e47a580a538b95541012b648)
Package internallib_v550 is named to resemble an internal private library and is published to the public npm registry, matching the classic dependency-confusion squat pattern. Its package.json description is 'pwn'. The single exported function command invokes child_process.exec to spawn /bin/bash -c id and logs the string 'infected' on the consumer host. The payload does not run at install or import time; it fires when consumer code calls the exported function. The name-squat intent, self-labeling as 'pwn', and shell-out on the exported API together form a dependency-confusion attack payload rather than a legitimate library.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes