Core runtime for Whalent Agent
OpenSSF/OSV advisory MAL-2026-10722 confirms this npm version as malicious. The package's main/bin entry (dist/index.cjs) implements a remote agent that opens a WebSocket to a gateway configured via WHALENT_GATEWAY / WHALENT_TOKEN / WHALENT_PLATFORM_URL and, over that channel, drives local PTY sessions via node-pty, spawns shells against process.env.SHELL, bridges loopback services on 127.0.0.1:3389 (RDP) and 127.0.0.1:5900/5901 (VNC), and runs a Python Jupyter kernel sidecar...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/jupyter_sidecar.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/index.cjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Package ships non-JavaScript build or shell helper files.
dist/jupyter_sidecar.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/index.cjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.cjsView on unpkg