OpenSSF/OSV advisory MAL-2026-6086 confirms this npm version as malicious. collect.js performs system reconnaissance and exfiltration to a hardcoded attacker-controlled host. The script imports child_process, os, fs, http, and https; reads os.hostname(), os.homedir(), and inspects local filesystem paths via fs.existsSync; and POSTs the collected data to http://aab.sportsontheweb.net (line 13/line 366)...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in ai-chat-helper (npm)
Details
collect.js performs system reconnaissance and exfiltration to a hardcoded attacker-controlled host. The script imports child_process, os, fs, http, and https; reads os.hostname(), os.homedir(), and inspects local filesystem paths via fs.existsSync; and POSTs the collected data to http://aab.sportsontheweb.net (line 13/line 366). The destination is an unrelated third-party domain over cleartext HTTP, with no relationship to any documented chat-helper functionality. This is the canonical credential/host-info beacon shape: child_process for command execution, os for host identity, fs for local file enumeration, and a hardcoded HTTP POST to an attacker domain.
Decision reason
OpenSSF Malicious Packages via OSV confirms ai-chat-helper@1.0.1 as malicious (MAL-2026-6086): Malicious code in ai-chat-helper (npm)