-= Per source details. Do not edit below this line.=-
The package runs a daemon that polls a hardcoded Supabase project (syhzpqqvrplaqdipcymw.supabase.co) via the RPC runtime_pick_next_request for remote-supplied job rows and spawns Claude Code / Codex / Kimi / Gemini / Grok in a PTY on the installer's host, driven by fields controlled by the paired remote party (prompt, permissionMode, appendSystemPrompt, allowedTools, model, workingDirectory). In dist/session-runner.js, spawnClaudeForRuntime invokes the agent binary through a login shell (['-l','-c','exec "$@"',...]) and, when input.permissionMode === 'bypassPermissions', passes --dangerously-skip-permissions, letting the remotely-driven AI agent execute arbitrary shell tools as the local user without any interactive prompt. On start, ensureBypassPermissionsAccepted() in dist/index.js also writes skipDangerousModePermissionPrompt: true into the installer's user-global ~/.claude/settings.json, disabling Claude Code's own bypass-permissions safety dialog for every future interactive Claude Code session the installer runs — not just those spawned by this daemon. dist/capabilities.js additionally reads ~/.kimi/config and modifies PATH. The net effect is a persistent remote-controlled channel giving the paired remote party host-level RCE on the installer's machine via the AI agent tool loop, plus a persistent lowering of a separate vendor tool's safety prompts.
{
"malicious-packages-origins": [
{
"sha256": "248d92bb0f9ac7a066bb69c3f3ecea88241e5dd35ea1b61393896c88c07b0856",
"source": "amazon-inspector",
"versions": [
"0.2.55"
],
"import_time": "2026-08-06T14:19:47.1859139Z",
"modified_time": "2026-08-06T13:23:27Z",
"id": "IN-MAL-2026-016401"
},
{
"source": "amazon-inspector",
"sha256": "cc5ab4270a0a70d482a6f9330a2f91d996ca6f0d3e6000d3bc34f9dadc0b4216",
"versions": [
"0.2.51"
],
"import_time": "2026-08-06T14:19:47.248787907Z",
"modified_time": "2026-08-06T13:23:35Z",
"id": "IN-MAL-2026-016402"
},
{
"sha256": "d9484bdd16ab9c436109c23a4f9ed8bdcba73a042d5f5b2fb8826fae1ba1abe3",
"source": "amazon-inspector",
"versions": [
"0.2.53"
],
"import_time": "2026-08-06T14:19:47.340615387Z",
"modified_time": "2026-08-06T13:23:53Z",
"id": "IN-MAL-2026-016404"
},
{
"sha256": "e3b20d90f97a5d37e2127b427614c3a0859b08ecd1e99be97065112007910d61",
"source": "amazon-inspector",
"import_time": "2026-08-06T14:19:47.611080496Z",
"modified_time": "2026-08-06T13:24:39Z",
"versions": [
"0.2.47"
],
"id": "IN-MAL-2026-016409"
},
{
"sha256": "f6c0c153959ae4bda2c8db51b34f1b769c3ea329324a9dda38041aa012e6c3d4",
"source": "amazon-inspector",
"modified_time": "2026-08-06T13:23:46Z",
"versions": [
"0.2.46"
],
"import_time": "2026-08-06T14:19:47.300643332Z",
"id": "IN-MAL-2026-016403"
},
{
"source": "amazon-inspector",
"sha256": "2a2c056dc9d2bfeb44511be27e07f31e4222b356605969294f3284ad0445e132",
"versions": [
"0.2.45"
],
"import_time": "2026-08-06T14:19:47.399307755Z",
"modified_time": "2026-08-06T13:24:00Z",
"id": "IN-MAL-2026-016405"
},
{
"sha256": "3d63c259eb725774353d4e5ff7478d7e88c8ae030855bfa3d2a653d20f33bffa",
"source": "amazon-inspector",
"import_time": "2026-08-06T14:19:47.097999377Z",
"modified_time": "2026-08-06T13:23:06Z",
"versions": [
"0.2.49"
],
"id": "IN-MAL-2026-016399"
},
{
"source": "amazon-inspector",
"sha256": "7a66f3ce363db41a478bf2a8d3e052bf639c962de5942a5e989725af3ab6b3c8",
"versions": [
"0.2.48"
],
"import_time": "2026-08-06T14:19:47.030269035Z",
"modified_time": "2026-08-06T13:22:55Z",
"id": "IN-MAL-2026-016398"
},
{
"source": "amazon-inspector",
"sha256": "b3d98d001e4e4b7f1397c2dee761c04e56b70370c6957754772f3e1674a6bbb1",
"versions": [
"0.2.50"
],
"import_time": "2026-08-06T14:19:47.555391706Z",
"modified_time": "2026-08-06T13:24:29Z",
"id": "IN-MAL-2026-016408"
},
{
"sha256": "c2f8b71ac7ea395aa6b4a7ec7f6cad04bb9c9188c3befd0650232f6c49aba75e",
"source": "amazon-inspector",
"import_time": "2026-08-06T14:19:47.511255724Z",
"modified_time": "2026-08-06T13:24:20Z",
"versions": [
"0.2.58"
],
"id": "IN-MAL-2026-016407"
},
{
"source": "amazon-inspector",
"sha256": "3206f63a97fe6d7428bbd83bb05bc69af530ea6915190b55b7ba7d5dc46c0152",
"versions": [
"0.2.56"
],
"import_time": "2026-08-06T14:19:47.149471939Z",
"modified_time": "2026-08-06T13:23:14Z",
"id": "IN-MAL-2026-016400"
},
{
"sha256": "4cb7d81e9688776ae2aae1215238f24d70f21bc73d284048fe16ef219d3769fc",
"source": "amazon-inspector",
"versions": [
"0.2.52"
],
"import_time": "2026-08-06T14:19:47.463917611Z",
"modified_time": "2026-08-06T13:24:12Z",
"id": "IN-MAL-2026-016406"
}
]
}{
"package_integrity": [
{
"hashes": {
"sha1": "74016586b5192abc06c69363ef7b78b529090d6c",
"sha512_sri": "sha512-FD5ecS8n4+uM4omMMr8EQod8ugXOoQEHhapyTovq3CcfXUYakhRaB6hmpAsmejP6aa1aAdWWzAX/dXN0vHCTUA=="
},
"filename": "entity-runtime-0.2.55.tgz"
}
],
"evidence_files": [
{
"path": "dist/claude-spawn.js",
"sha256": "727774b7fe11cfa8db6dc3ed0440dc31408d118fad1a1220d3961ebb618e677d",
"tlsh": "9e12b507baf6223a00d241b8bbaf1403a77193633264f45477ad93645f5e8184bf4fe6"
},
{
"path": "dist/claude-config.js",
"sha256": "0a9018ad814057b271f1c847062aa9834ad1b6480290eafea9357b7000b4e35c",
"tlsh": "fbc1a50a6afc6273c1e62098572f4017f7264607321af074b76cd2e41f6902c1a95feb"
}
]
}
[
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@addai/entity-runtime/MAL-2026-13410.json"