MAL-2026-13411

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@addai/node/MAL-2026-13411.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13411
Published
2026-08-06T13:21:23Z
Modified
2026-08-06T14:34:57.852711042Z
Summary
Malicious code in @addai/node (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6ca685518d56ea513609a2dfcd845bb14d94c3faaf58645553c688ca59817921)

The package installs a background daemon (dist/session-runner.js) that pairs the host to a remote +Ai account and polls a hardcoded Supabase backend at syhzpqqvrplaqdipcymw.supabase.co for request rows. Fields from each row — prompt, workingdirectory, ephemeralgitremote(s), permissionmode, allowedtools, mcpsoverride, agent (including 'claude-bypass') — are passed to local spawn/pty.spawn calls that launch installed AI-agent CLIs (claude, codex, kimi, gemini, grok) on the installer's machine, giving whoever controls the remote account the ability to run those agents with arbitrary prompts, in arbitrary working directories, against arbitrary git remotes, and with elevated permission modes. The same channel accepts installharness, updateruntime, setautostart, and logoutharness commands, and runs npm install -g <spec.npmPackage> driven by rpc('runtimecommandspick',...), providing remote install/update and autostart persistence. probeCapabilities() additionally reads third-party AI CLI credential stores it does not own (~/.codex/auth.json, ~/.kimi-code/credentials/*.json, ~/.kimi/config, ~/.gemini/oauthcreds.json, ~/.gemini/googleaccounts.json, ~/.gemini/.env, ~/.grok/auth.json, and claude auth status output) and reports authed state, account kind, account email, and CLI versions to the same Supabase backend via runtime_heartbeat. dist/capabilities.js also modifies PATH and touches ~/.kimi/config. The network→shell/PTY/exec dataflow, remote-driven package installation, and enumeration of unrelated AI-CLI credential stores together constitute a remote-access channel into the installer's host.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-08-06T13:22:45Z",
            "id": "IN-MAL-2026-016397",
            "import_time": "2026-08-06T14:19:46.9875309Z",
            "versions": [
                "0.9.0"
            ],
            "source": "amazon-inspector",
            "sha256": "1b1383594978b2f86bf71586b799e9d5ed0e5d8454c42ff03934da68bbc3e305"
        },
        {
            "modified_time": "2026-08-06T13:22:38Z",
            "id": "IN-MAL-2026-016396",
            "import_time": "2026-08-06T14:19:46.943909886Z",
            "versions": [
                "0.8.2"
            ],
            "source": "amazon-inspector",
            "sha256": "b5ae65ab36c5e8925f0e7e1ae61ac7e0344354f76e705597f0f093e4d98d3957"
        },
        {
            "modified_time": "2026-08-06T13:22:11Z",
            "id": "IN-MAL-2026-016393",
            "import_time": "2026-08-06T14:19:46.755159216Z",
            "versions": [
                "0.5.0"
            ],
            "source": "amazon-inspector",
            "sha256": "c7a8adf2beb431c9dff82ae68061915dbf051b58a04ae25c9b188154faf44b7a"
        },
        {
            "modified_time": "2026-08-06T13:22:02Z",
            "id": "IN-MAL-2026-016392",
            "import_time": "2026-08-06T14:19:46.710921356Z",
            "versions": [
                "0.7.0"
            ],
            "source": "amazon-inspector",
            "sha256": "f5e5500857c10a972e41213477ad0da60ed23c76ae51a96fe8a01400069e718e"
        },
        {
            "modified_time": "2026-08-06T13:22:30Z",
            "id": "IN-MAL-2026-016395",
            "import_time": "2026-08-06T14:19:46.898028153Z",
            "versions": [
                "0.11.0"
            ],
            "source": "amazon-inspector",
            "sha256": "ff41ecac1194cca87e881efc49710e7962de4bf0cc67a94d7e9056ccaa8aff5a"
        },
        {
            "versions": [
                "0.8.1"
            ],
            "id": "IN-MAL-2026-016391",
            "import_time": "2026-08-06T14:19:46.667963931Z",
            "modified_time": "2026-08-06T13:21:54Z",
            "source": "amazon-inspector",
            "sha256": "5e1ed9851cd03cba7702ba7add976fb5b73deedc3933b1ee9cf0ec19d550ab44"
        },
        {
            "versions": [
                "0.11.2"
            ],
            "id": "IN-MAL-2026-016394",
            "import_time": "2026-08-06T14:19:46.832915881Z",
            "modified_time": "2026-08-06T13:22:18Z",
            "source": "amazon-inspector",
            "sha256": "6ca685518d56ea513609a2dfcd845bb14d94c3faaf58645553c688ca59817921"
        },
        {
            "modified_time": "2026-08-06T13:21:44Z",
            "id": "IN-MAL-2026-016390",
            "import_time": "2026-08-06T14:19:46.624787871Z",
            "versions": [
                "0.8.0"
            ],
            "source": "amazon-inspector",
            "sha256": "b493c3a6e0c0b056aaddb819e9412f044e3e87f063e6c957a8815bf00b44dbf7"
        },
        {
            "modified_time": "2026-08-06T13:21:23Z",
            "id": "IN-MAL-2026-016388",
            "import_time": "2026-08-06T14:19:46.54734459Z",
            "versions": [
                "0.11.1"
            ],
            "source": "amazon-inspector",
            "sha256": "dd19db9511a6b5a1b78df056eee067474a7ab4df09495c777fb3b3a62b6f3c59"
        },
        {
            "versions": [
                "0.4.0"
            ],
            "id": "IN-MAL-2026-016389",
            "import_time": "2026-08-06T14:19:46.592570565Z",
            "modified_time": "2026-08-06T13:21:36Z",
            "source": "amazon-inspector",
            "sha256": "e402a98b450e9139ddc3a17df8dc22cb1c8d0d7e2af589bd3193ab8ba4d5c459"
        }
    ]
}
References
Credits

Affected packages

npm / @addai/node

Package

Affected ranges

Affected versions

0.*
0.4.0
0.5.0
0.7.0
0.8.0
0.8.1
0.8.2
0.9.0
0.11.0
0.11.1
0.11.2

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "node-0.9.0.tgz",
            "hashes": {
                "sha512_sri": "sha512-lX4vZFRVoiymKuvRuHkSqx1khv52OWEv7XFsfhQQ4zY34cDG06lcYguD9slXycl5sccJFc81J4rr6UmNXIntSA==",
                "sha1": "097fde49003253119f59ef7c81e9e849c5df9f13"
            }
        }
    ],
    "evidence_files": [
        {
            "path": "dist/request-pump.js",
            "tlsh": "4242d74b63b3123b5ea2546a6b2ff1d23b1491273246d4a1b40e83453f0653c92fbbdb",
            "sha256": "e12b3f401f2cb448e63c5bbb02fef67baf2bbccd308cca33cc70586c2650bb87"
        },
        {
            "path": "dist/command-runner.js",
            "tlsh": "42c2627921fb66343863e06d476b60122b2ea1173255cc90ba5cf7145fcd12a4aeaff8",
            "sha256": "ed9ef26d3a5059d2187c626223235ff4dab4b1907507dc22870b03ee3e90dedf"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@addai/node/MAL-2026-13411.json"