Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in aclade-agent (npm)

0
Critical
Published: 08/07/2026 (08/07/2026, 16:37:54 UTC)
Source: GCVE Database
Product: aclade-agent

Description

The aclade-agent npm package runs a daemon that polls a remote server for task objects and executes them with high privileges. These tasks include running arbitrary shell commands, reading and writing arbitrary files, performing recursive directory listings, searching file contents, and scheduling persistent cron jobs. The daemon also auto-updates itself by fetching the latest package version from the npm registry and reinstalling it, enabling automatic execution of any future malicious updates. This design grants the remote server full remote code execution and persistent control over any host running the agent with elevated privileges.

Affected software

npmghsa
aclade-agent
Affected versions
=1.0.5=1.0.2=1.0.1=1.0.6=1.0.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 15:39:33 UTC

Technical Analysis

The aclade-agent npm package operates a daemon that continuously polls https://aclade.com/api/connector/poll for task objects. These tasks allow execution of arbitrary shell commands via child_process.spawn with shell:true, arbitrary filesystem read/write/replace operations, recursive directory listings, grep searches, and scheduling of cron jobs that persist across reboots. All task parameters come directly from the remote server, effectively granting it full remote code execution and filesystem control on the host. Additionally, the daemon polls the npm registry hourly for new versions of aclade-agent and automatically installs and restarts itself with the latest version, enabling automatic deployment of any future malicious updates. The package is typically installed globally with sudo/PM2, meaning it runs with elevated privileges, increasing the severity of the threat.

Potential Impact

Hosts running aclade-agent are fully compromised, as the remote server can execute arbitrary code, manipulate any files, and maintain persistent access via scheduled cron jobs. The automatic update mechanism allows the attacker to push new malicious versions that will be installed and executed with elevated privileges without user intervention. This results in complete remote control and persistent compromise of affected systems.

Mitigation Recommendations

No official patch or remediation is currently documented. Due to the nature of the package, immediate removal of aclade-agent from all systems is recommended to eliminate the risk. Avoid installing or running this package, especially with elevated privileges. Monitor for any instances of aclade-agent running and uninstall it. Since the package auto-updates from the npm registry, blocking network access to the npm registry or aclade.com endpoints may mitigate further compromise. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13614
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a77432dbf8831d539b461c2

Added to database: 08/08/2026, 14:54:37 UTC

Last enriched: 08/08/2026, 15:39:33 UTC

Last updated: 08/08/2026, 23:55:37 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses