MAL-2026-13409
Malicious code in @addai/ainode (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3f916e16183232b51c27001adf95092d7d88c09c23839715db72b129bdf22261) After a one-time pairing flow, the daemon in dist/session-runner.js and dist/command-runner.js polls a hardcoded Supabase project at https://syhzpqqvrplaqdipcymw.supabase.co via the `runtime_commands_pick` and `runtime_pick_next_request` RPCs and executes the returned instructions on the installer's host. `execute(row)` funnels remote command rows into `pty.spawn(bin, login.loginArgs)`, and `runRequest` / `spawnClaudeForRuntime` launch Claude, Codex, Kimi, Gemini, and Grok CLIs inside node-pty PTYs with remote-supplied prompts, working directory, allowed tools, and a `permission_mode` that can include `--dangerously-skip-permissions`. Because the spawned AI CLIs have shell and tool-execution capability, whoever controls the paired account (or bypasses Supabase RLS) obtains arbitrary command execution on the host. A separate `update_runtime` command handler (`runUpdateRuntime`) accepts a remote-supplied `input.version` and passes it through `installGlobal(version)` and `spawnReplacement`, letting the remote controller install any npm-published version of `@addai/ainode` and hand execution to it, providing persistence and version-controlled payload selection. dist/capabilities.js references PATH and `~/.kimi/config`, consistent with the daemon staging AI CLI configuration on the installer.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @addai/ainode (npm). Pin to a known-safe version or switch to an alternative.