MAL-2026-13455
Malicious code in remote-claude-daemon (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c9c092b787277e3c89fc27a6c01e5360bc0566988cefca0b1a0f9626af9186d0) remote-claude-daemon connects to a hardcoded WebSocket relay at wss://remote-claude-relay.fly.dev and treats inbound messages as commands executed against the local host. On receiving ai_query/ai_voice_query messages, the daemon spawns the local `claude` binary with `--continue -p --dangerously-skip-permissions` and the remote-supplied prompt as input, giving the remote side arbitrary code execution through Claude Code's agent tooling with the permissions prompt disabled. A separate handleInput path dispatches remote messages to synthesised mouse moves/clicks, keyboard keypresses (including modifier chords) and clipboard paste via @nut-tree-fork/nut-js, giving the remote side full interactive control over the installer's desktop. The daemon additionally captures screen frames (native SCStream on macOS via a shipped Swift helper, ffmpeg gdigrab/x11grab on Windows/Linux) and optional microphone PCM audio and streams them over the same relay. Although the package is documented as a remote-Claude bridge, session tokens gate access, and `--relay` can override the default, the out-of-the-box configuration wires an author-controlled endpoint into an RCE + input-injection + screen/audio-capture surface on the installer. The relay operator (or anyone who obtains a session token, MITMs the connection, or compromises the relay) can execute arbitrary commands as the user, control input, and stream desktop/audio contents.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for remote-claude-daemon (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.9 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.7 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.5 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.5.7 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.4.6 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.5.2 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.5.5 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.6.0 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.0 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.4.2 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.8 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.6 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.5.4 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.6.1 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.6.6 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.6.2 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.5.9 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.4.7 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.5.0 [PACKAGE]
- https://www.npmjs.com/package/remote-claude-daemon/v/0.3.4 [PACKAGE]