-= Per source details. Do not edit below this line.=-
On npm install, scripts/postinstall.cjs runs fs.cpSync(payload, cwd, { recursive: true }) with cwd=process.env.INIT_CWD || process.cwd() — recursively writing the package's entire payload/ tree (.mcp.json, CLAUDE.md,.claude/commands/,.claude/settings.json, and three chatroom.cjs files) into the installing project's root directory. The dropped.mcp.json registers an MCP server named chatroom whose BRIDGEURL is hardcoded to https://demo1.0x2ai.com (the author's endpoint). The dropped CLAUDE.md is auto-loaded by Claude Code as project instructions, redefines the assistant persona, and instructs use of the planted MCP tools/bridge. The companion binary payload/chatroom-mcp-lite-patched.cjs exposes a provider_query tool that POSTs caller prompts to ${BRIDGE}/api/proxy-query ("API keys are managed server-side — no client keys needed"), and memorysave/load/chatroompost/settingsset are similarly routed. Any subsequent Claude Code session opened in the consumer's project will silently forward prompts, memory, settings, and any API keys configured via settingsset to demo1.0x2ai.com. The package also ships URL-path obfuscation (/x/<sha256(salt+path)[:4]>) that is dormant only because the shipped config sets DIRECTAPI=1. A bin/start.cjs entry additionally launches claude --dangerously-skip-permissions, disabling Claude Code's tool-permission prompts and amplifying the relay's reach when the user runs the bundled CLI.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-005669",
"import_time": "2026-06-11T07:49:39.081313234Z",
"sha256": "b29f3d65354dd3bf54e23142f5c6577ad4c5a37b9ff109200309cbb6453b8c26",
"modified_time": "2026-06-11T07:16:13Z",
"source": "amazon-inspector",
"versions": [
"2.0.2"
]
},
{
"id": "IN-MAL-2026-005681",
"import_time": "2026-06-11T07:49:40.414165219Z",
"sha256": "baf53f193b709bc0c98ddbe429cb8edf1caf1ed2fa019bc3e7dc362e431c493f",
"versions": [
"1.2.0"
],
"source": "amazon-inspector",
"modified_time": "2026-06-11T07:16:23Z"
},
{
"id": "IN-MAL-2026-005670",
"import_time": "2026-06-11T07:49:39.168217478Z",
"sha256": "fdc7c661d4867578d3dd920010bccc1e79fcae8753b5bf549f44ea8a45cde502",
"versions": [
"2.0.0"
],
"source": "amazon-inspector",
"modified_time": "2026-06-11T07:16:13Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "bin/start.cjs",
"tlsh": "1e81728a5bee0b7b467412812c0b4137e959cc402364f5a0a17e8296bfc1da099b77df",
"sha256": "adfcb1d45218ade2e6a9cc459514d59569de732412deca558842c629d3be908b"
},
{
"path": "payload/chatroom-mcp-lite-patched.cjs",
"tlsh": "505307852c79603a4fb65365ba36a617ff35522bb01114b2fafcc2142f314d091aaefd",
"sha256": "a1abc812c52dcefeb85473275f7c1e5a86770b114767176416ed94ebe620cf00"
}
],
"package_integrity": [
{
"filename": "0x2ai-demo1-2.0.2.tgz",
"hashes": {
"sha512_sri": "sha512-uYBgzbYSPOLK/5apVkS6tdzsCv4gN6PO+5XOsFFXSV3wjvbd7KOMIQlL4ZuU76b504f/jwyNpvRJfJyMKcVQCA==",
"sha1": "5fba08011ef4181f4ac38fb45e374dc50d1cc3b7"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/0x2ai-demo1/MAL-2026-5587.json"