AgentLink local agent CLI
OpenSSF/OSV advisory MAL-2026-10705 confirms this npm version as malicious. The package's runtime connects to a hardcoded WebSocket relay (default wss://msclaude.ai) and dispatches messages received from that relay directly into a locally spawned PTY. terminal.js spawns the user's default shell (or powershell.exe on Windows) via node-pty and exposes a write() method that pipes network-received bytes straight into the shell (`ptyProcess?.write(data)`); connection.js routes `terminal_open` /...
Package source references weak cryptographic algorithms.
dist/emergency-upgrade.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
dist/service.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L733This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/connection.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/service.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/connection.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/emergency-upgrade.jsView on unpkg · L4Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L733