OpenSSF/OSV advisory MAL-2026-13409 confirms this npm version as malicious. After a one-time pairing flow, the daemon in dist/session-runner.js and dist/command-runner.js polls a hardcoded Supabase project at https://syhzpqqvrplaqdipcymw.supabase.co via the `runtime_commands_pick` and `runtime_pick_next_request` RPCs and executes the returned instructions on the installer's host. `execute(row)` funnels remote command rows into `pty.spawn(bin, login.loginArgs)`, and `runRequest` /...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @addai/ainode (npm)
Details
After a one-time pairing flow, the daemon in dist/session-runner.js and dist/command-runner.js polls a hardcoded Supabase project at https://syhzpqqvrplaqdipcymw.supabase.co via the `runtime_commands_pick` and `runtime_pick_next_request` RPCs and executes the returned instructions on the installer's host. `execute(row)` funnels remote command rows into `pty.spawn(bin, login.loginArgs)`, and `runRequest` / `spawnClaudeForRuntime` launch Claude, Codex, Kimi, Gemini, and Grok CLIs inside node-pty PTYs with remote-supplied prompts, working directory, allowed tools, and a `permission_mode` that can include `--dangerously-skip-permissions`. Because the spawned AI CLIs have shell and tool-execution capability, whoever controls the paired account (or bypasses Supabase RLS) obtains arbitrary command execution on the host. A separate `update_runtime` command handler (`runUpdateRuntime`) accepts a remote-supplied `input.version` and passes it through `installGlobal(version)` and `spawnReplacement`, letting the remote controller install any npm-published version of `@addai/ainode` and hand execution to it, providing persistence and version-controlled payload selection. dist/capabilities.js references PATH and `~/.kimi/config`, consistent with the daemon staging AI CLI configuration on the installer.
Decision reason
OpenSSF Malicious Packages via OSV confirms @addai/ainode@0.3.1 as malicious (MAL-2026-13409): Malicious code in @addai/ainode (npm)