One-command macOS executor onboarding for Sun Yiting's private company resource pool
OpenSSF/OSV advisory MAL-2026-16443 confirms this npm version as malicious. Running `npx my-company-device` appends a hardcoded ssh-ed25519 public key labelled `sunyiting-macmini` to the installer's `~/.ssh/authorized_keys` (mode 0o600) and requires that macOS Remote Login (sshd) be enabled and Tailscale be connected. The tool also copies `device-worker.mjs` into `~/.my-company-device/scripts/`, which reads a JSON request from stdin and spawns `codex` or `claude` with caller-supplied argv,...
This report applies to my-company-device@0.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.