OpenSSF/OSV advisory MAL-2026-13370 confirms this npm version as malicious. On npm install, postinstall.js unconditionally runs runSetup() which wires the package into the installer's AI tooling and stands up long-lived collection infrastructure before any consent dialog is shown. A baked defaults.json sets egressUrl to a hardcoded ephemeral Cloudflare Quick Tunnel (mime-bind-border-using.trycloudflare.com). CursorTailer, ClaudeTailer, and CodexTailer walk...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in llm-interceptor (npm)
Details
On npm install, postinstall.js unconditionally runs runSetup() which wires the package into the installer's AI tooling and stands up long-lived collection infrastructure before any consent dialog is shown. A baked defaults.json sets egressUrl to a hardcoded ephemeral Cloudflare Quick Tunnel (mime-bind-border-using.trycloudflare.com). CursorTailer, ClaudeTailer, and CodexTailer walk ~/.cursor/projects/*/agent-transcripts and Claude transcript paths, parse user and assistant turns, and POST the prompt/response content to /v1/raw at that tunnel; a Claude SessionEnd hook and a baseline proxy do the same. reportHeartbeat POSTs {deviceId, tenantId, username, hostname, version, consent, proxyUp, egressUrl} to /v1/agents/heartbeat every 15 minutes regardless of consent, and default identifiers ('friend-token', 'friend-laptop') indicate the collection is aimed at the installer. registerAutostart drops a hidden PowerShell watchdog under ~/.llm-interceptor and installs three redundant Windows persistence mechanisms (a Scheduled Task with ONLOGON trigger, 5-minute pulse, and RestartOnFailure; an HKCU\...\Run key; and a shortcut in the Startup folder) so the collector respawns across reboots. maybeSelfUpdate() polls the same collector for a bundleVersion field and, when the remote value parses as newer, executes `npm install -g llm-interceptor@<tag>` (tag sourced from env, default 'latest') and restarts the watchdog, giving the operator of the tunnel arbitrary code execution on the installer's host at any later time. Declining the post-install consent prompt does not remove the MCP integrations (~/.cursor/mcp.json, `claude mcp add`, ~/.claude/settings.json SessionEnd hook), autostart entries, or heartbeat.