MAL-2026-13455

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/remote-claude-daemon/MAL-2026-13455.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13455
Published
2026-08-06T19:57:03Z
Modified
2026-08-06T23:50:19.392355253Z
Summary
Malicious code in remote-claude-daemon (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c9c092b787277e3c89fc27a6c01e5360bc0566988cefca0b1a0f9626af9186d0)

remote-claude-daemon connects to a hardcoded WebSocket relay at wss://remote-claude-relay.fly.dev and treats inbound messages as commands executed against the local host. On receiving aiquery/aivoice_query messages, the daemon spawns the local claude binary with --continue -p --dangerously-skip-permissions and the remote-supplied prompt as input, giving the remote side arbitrary code execution through Claude Code's agent tooling with the permissions prompt disabled. A separate handleInput path dispatches remote messages to synthesised mouse moves/clicks, keyboard keypresses (including modifier chords) and clipboard paste via @nut-tree-fork/nut-js, giving the remote side full interactive control over the installer's desktop. The daemon additionally captures screen frames (native SCStream on macOS via a shipped Swift helper, ffmpeg gdigrab/x11grab on Windows/Linux) and optional microphone PCM audio and streams them over the same relay. Although the package is documented as a remote-Claude bridge, session tokens gate access, and --relay can override the default, the out-of-the-box configuration wires an author-controlled endpoint into an RCE + input-injection + screen/audio-capture surface on the installer. The relay operator (or anyone who obtains a session token, MITMs the connection, or compromises the relay) can execute arbitrary commands as the user, control input, and stream desktop/audio contents.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-016840",
            "import_time": "2026-08-06T23:25:11.919982696Z",
            "sha256": "0cc04b385ce0585b65983f0a9800753ae9000d6506fbdd1f1ab0fd9591dc2643",
            "versions": [
                "0.3.9"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:59:32Z"
        },
        {
            "id": "IN-MAL-2026-016830",
            "import_time": "2026-08-06T23:25:11.492150109Z",
            "sha256": "50134d71be77b2111f5b2cc42083ee520f5763483c5ef9dd0fe9aa14a52ff9d5",
            "versions": [
                "0.3.7"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:58:07Z"
        },
        {
            "id": "IN-MAL-2026-016838",
            "import_time": "2026-08-06T23:25:11.844299368Z",
            "sha256": "a72c85f56c6186749a871921c442a4c2711cf2df0d670a33b807c0ce6343fbd8",
            "modified_time": "2026-08-06T19:59:14Z",
            "source": "amazon-inspector",
            "versions": [
                "0.3.5"
            ]
        },
        {
            "id": "IN-MAL-2026-016841",
            "import_time": "2026-08-06T23:25:11.953840318Z",
            "sha256": "e43c80e65e48e1ec6433a1c852417322053c8a0821c6dc217cdfc3132b8e1d65",
            "modified_time": "2026-08-06T19:59:40Z",
            "source": "amazon-inspector",
            "versions": [
                "0.5.7"
            ]
        },
        {
            "id": "IN-MAL-2026-016824",
            "import_time": "2026-08-06T23:25:11.248013875Z",
            "sha256": "e54c94a33cacd1f687a1f98ce1f643fc974757d24b1b3eeeb89cf733edcd5112",
            "modified_time": "2026-08-06T19:57:11Z",
            "source": "amazon-inspector",
            "versions": [
                "0.4.6"
            ]
        },
        {
            "id": "IN-MAL-2026-016842",
            "import_time": "2026-08-06T23:25:12.004416819Z",
            "sha256": "6ffaf23dc23ad649fbff35601d721add3231336aeb914e3129017a48b40836ba",
            "versions": [
                "0.5.2"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:59:48Z"
        },
        {
            "id": "IN-MAL-2026-016827",
            "import_time": "2026-08-06T23:25:11.397126423Z",
            "sha256": "7299ef4f42a0465f6d27d7932857f00b2c8fd133ba9bc0f5a97eb98768cf1eaf",
            "versions": [
                "0.5.5"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:57:38Z"
        },
        {
            "import_time": "2026-08-06T23:25:11.178394824Z",
            "id": "IN-MAL-2026-016823",
            "sha256": "9ad1628dace09d9945234d24dfbf8460e044bd303bdac8d37b2ae3e77af3daa2",
            "modified_time": "2026-08-06T19:57:03Z",
            "source": "amazon-inspector",
            "versions": [
                "0.6.0"
            ]
        },
        {
            "id": "IN-MAL-2026-016831",
            "import_time": "2026-08-06T23:25:11.559680948Z",
            "sha256": "a720602241452b95fbb1bd58f9a4e407cbd5c56a5945f90d92a2103ddb4755a2",
            "modified_time": "2026-08-06T19:58:15Z",
            "source": "amazon-inspector",
            "versions": [
                "0.3.0"
            ]
        },
        {
            "id": "IN-MAL-2026-016837",
            "import_time": "2026-08-06T23:25:11.811648908Z",
            "sha256": "c9c092b787277e3c89fc27a6c01e5360bc0566988cefca0b1a0f9626af9186d0",
            "versions": [
                "0.4.2"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:59:06Z"
        },
        {
            "id": "IN-MAL-2026-016828",
            "import_time": "2026-08-06T23:25:11.425839781Z",
            "sha256": "d39ae95f369db5d8e9e20835caf67b4faa5e6a3f9359598e5612923c39307c22",
            "modified_time": "2026-08-06T19:57:49Z",
            "source": "amazon-inspector",
            "versions": [
                "0.3.8"
            ]
        },
        {
            "id": "IN-MAL-2026-016829",
            "import_time": "2026-08-06T23:25:11.4556546Z",
            "sha256": "e5e42c8fbbd44722f748855ec2a2d4827bb81dec178dc00bc82f6d9af3829bd2",
            "versions": [
                "0.3.6"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:57:59Z"
        },
        {
            "import_time": "2026-08-06T23:25:11.662874478Z",
            "id": "IN-MAL-2026-016833",
            "sha256": "30ce1f921742260706c6eb2ea95030a8b8f68c72d8558cb886f40ce1e098a5f4",
            "modified_time": "2026-08-06T19:58:33Z",
            "source": "amazon-inspector",
            "versions": [
                "0.5.4"
            ]
        },
        {
            "id": "IN-MAL-2026-016834",
            "import_time": "2026-08-06T23:25:11.709344919Z",
            "sha256": "5409ee612b4b78d004abcd66a068bd4528955058775d036e110cdf251147673a",
            "versions": [
                "0.6.1"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:58:42Z"
        },
        {
            "id": "IN-MAL-2026-016832",
            "import_time": "2026-08-06T23:25:11.620168317Z",
            "sha256": "990358496227dbad6bfee52cd7347d719faefd55706c10d4997c5c37a4e7dc7d",
            "modified_time": "2026-08-06T19:58:24Z",
            "source": "amazon-inspector",
            "versions": [
                "0.6.6"
            ]
        },
        {
            "id": "IN-MAL-2026-016826",
            "import_time": "2026-08-06T23:25:11.338561556Z",
            "sha256": "a7019993eb984de1e92741ebe82f5b7e4979ec53c1183346709c35d5570d5642",
            "versions": [
                "0.6.2"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T19:57:30Z"
        },
        {
            "id": "IN-MAL-2026-016836",
            "import_time": "2026-08-06T23:25:11.77216931Z",
            "sha256": "c793a392c49c28554c2a9cc08f6b624c1b74053f931838fba523ede41ffdfce9",
            "modified_time": "2026-08-06T19:58:59Z",
            "source": "amazon-inspector",
            "versions": [
                "0.5.9"
            ]
        },
        {
            "import_time": "2026-08-06T23:25:11.291325019Z",
            "id": "IN-MAL-2026-016825",
            "sha256": "e1097341da0486b1c28d3832da222a07870523da997f3706180f8554faf8fe37",
            "modified_time": "2026-08-06T19:57:20Z",
            "source": "amazon-inspector",
            "versions": [
                "0.4.7"
            ]
        },
        {
            "import_time": "2026-08-06T23:25:11.876134957Z",
            "id": "IN-MAL-2026-016839",
            "sha256": "f1af8e496aec6ca98a7745973c975b57171e3d5172329b0c7e6485754824fb6a",
            "modified_time": "2026-08-06T19:59:22Z",
            "source": "amazon-inspector",
            "versions": [
                "0.5.0"
            ]
        },
        {
            "id": "IN-MAL-2026-016835",
            "import_time": "2026-08-06T23:25:11.734958179Z",
            "sha256": "45b583bf566b2e76ef5fffb777a63d8b572ff6598b8ee312424f8fee2806d567",
            "modified_time": "2026-08-06T19:58:49Z",
            "source": "amazon-inspector",
            "versions": [
                "0.3.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / remote-claude-daemon

Package

Name
remote-claude-daemon
View open source insights on deps.dev
Purl
pkg:npm/remote-claude-daemon

Affected ranges

Affected versions

0.*
0.3.0
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.2
0.4.6
0.4.7
0.5.0
0.5.2
0.5.4
0.5.5
0.5.7
0.5.9
0.6.0
0.6.1
0.6.2
0.6.6

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/remote-claude-daemon/MAL-2026-13455.json"
indicators
{
    "evidence_files": [
        {
            "path": "cli.js",
            "tlsh": "3b22968599f900320b4270f0b89b614a37f696233b4e8990776df3692f96c74cdb2b5d",
            "sha256": "64dc1b50be8626888195ca647f0c0224cb45ce9a23c17c00fa7670619f669f63"
        }
    ],
    "package_integrity": [
        {
            "filename": "remote-claude-daemon-0.3.9.tgz",
            "hashes": {
                "sha1": "c252ea3644d3a04a4c94c649ec6a18c0fc697f73",
                "sha512_sri": "sha512-rM+e+gleiFxfWKZ/ZWxphECmUDxBrmYHVMPlETFj5TF9W0prMgIIyWY8PaHYxBRPnIPNWuMk4+HxY8tcBYDxSA=="
            }
        }
    ]
}