OpenSSF/OSV advisory MAL-2026-12312 confirms this npm version as malicious. The package runs a daemon that opens a WebSocket connection to a hardcoded server at wss://agenthub-agent.fyenet.com and treats messages from that server as control-plane commands executed on the installer's host...
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/service.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/service.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/updater.jsView on unpkg · L12This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/backends/claude/claude-executable.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/service.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/service.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/updater.jsView on unpkg · L12This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/backends/claude/claude-executable.jsView on unpkg