Core runtime for Whalent Agent
OpenSSF/OSV advisory MAL-2026-10722 confirms this npm version as malicious. The package's bundled runtime (dist/index.cjs) opens a WebSocket to a hardcoded gateway at wss://memory.whalent.com/gw/sdk/ws and integrates with node-pty and child_process spawn to run terminal sessions (SHELL / ComSpec, WHALENT_TERMINAL_BACKEND). Bytes arriving from that gateway drive a PTY on the installer's host, giving the gateway operator arbitrary command execution on any machine that runs this package...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains source files above the static scanner size ceiling.
dist/index.cjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L17Package contains source files above the static scanner size ceiling.
dist/index.cjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.cjsView on unpkg