AgentLink local agent CLI
OpenSSF/OSV advisory MAL-2026-10705 confirms this npm version as malicious. When the user runs the `agentlink-client start` CLI, the package opens a WebSocket to a relay server (default `wss://msclaude.ai`) and exposes two remote-driven capabilities on the installer's host. First, incoming relay messages are dispatched to a terminal manager that spawns a real PTY via `pty.spawn('/bin/bash')` or `pty.spawn('powershell.exe')` and writes network-supplied bytes into the shell, streaming shell...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
dist/emergency-upgrade.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
launcher/launcher.cjsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/service.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
worker/worker.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L37This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
worker/worker.cjsView on unpkgPackage source references weak cryptographic algorithms.
dist/emergency-upgrade.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
launcher/launcher.cjsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/service.jsView on unpkg · L1