Malicious code in agenthub-ai (npm)
The agenthub-ai npm package runs a persistent daemon that connects to a hardcoded WebSocket server controlled by the package maintainer or potentially an attacker who compromises that server. This daemon can execute server-supplied commands with broad file system access and spawn subprocesses, enabling full host control. It also supports a remote update mechanism that can force the installation of new code versions. Additionally, the package redirects native bindings to a placeholder package, which could be replaced later with malicious payloads. The daemon activates only when the package's binary is run, not during installation or import.
AI Analysis
Technical Summary
The agenthub-ai npm package versions 0.20.1, 0.20.2, 0.20.3, and 0.20.4 include a persistent daemon that opens a WebSocket connection to a hardcoded production endpoint (wss://agenthub-agent.fyenet.com). This connection allows the server to send commands that read, write, and search files on the host machine and spawn the local Claude Agent CLI with arbitrary prompts. The daemon's default permissions bypass restrictions, granting extensive control to the server operator or any party who compromises it. A documented 'update' action enables the server to stop the daemon, run 'npm install' to fetch the latest agenthub-ai version, and restart the daemon, effectively allowing forced remote code execution under the package's name. The package.json uses overrides to replace native subpackages with a stub package ([email protected]), which could be republished with malicious payloads, affecting all installers. The daemon only runs when the package's binary is executed, not during installation or when required as a module.
Potential Impact
Any party controlling the WebSocket server can execute arbitrary code with full host privileges on machines running the agenthub-ai daemon. This includes reading, writing, and searching files and spawning subprocesses with arbitrary commands. The remote update mechanism allows forced installation of new malicious code versions, escalating the risk of persistent compromise. The override of native bindings to a placeholder package introduces supply chain risk, as a malicious republish could affect all users of the package. This results in a high risk of full system compromise for users running the daemon.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid running the agenthub-ai package binary to prevent the daemon from starting. Since the daemon only activates when the binary is executed, not on install or require, refraining from running the binary mitigates immediate risk. Monitor the package's official repository and vendor advisories for updates or patches. Consider removing the package from systems where it is not essential. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in agenthub-ai (npm)
Description
The agenthub-ai npm package runs a persistent daemon that connects to a hardcoded WebSocket server controlled by the package maintainer or potentially an attacker who compromises that server. This daemon can execute server-supplied commands with broad file system access and spawn subprocesses, enabling full host control. It also supports a remote update mechanism that can force the installation of new code versions. Additionally, the package redirects native bindings to a placeholder package, which could be replaced later with malicious payloads. The daemon activates only when the package's binary is run, not during installation or import.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The agenthub-ai npm package versions 0.20.1, 0.20.2, 0.20.3, and 0.20.4 include a persistent daemon that opens a WebSocket connection to a hardcoded production endpoint (wss://agenthub-agent.fyenet.com). This connection allows the server to send commands that read, write, and search files on the host machine and spawn the local Claude Agent CLI with arbitrary prompts. The daemon's default permissions bypass restrictions, granting extensive control to the server operator or any party who compromises it. A documented 'update' action enables the server to stop the daemon, run 'npm install' to fetch the latest agenthub-ai version, and restart the daemon, effectively allowing forced remote code execution under the package's name. The package.json uses overrides to replace native subpackages with a stub package ([email protected]), which could be republished with malicious payloads, affecting all installers. The daemon only runs when the package's binary is executed, not during installation or when required as a module.
Potential Impact
Any party controlling the WebSocket server can execute arbitrary code with full host privileges on machines running the agenthub-ai daemon. This includes reading, writing, and searching files and spawning subprocesses with arbitrary commands. The remote update mechanism allows forced installation of new malicious code versions, escalating the risk of persistent compromise. The override of native bindings to a placeholder package introduces supply chain risk, as a malicious republish could affect all users of the package. This results in a high risk of full system compromise for users running the daemon.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid running the agenthub-ai package binary to prevent the daemon from starting. Since the daemon only activates when the binary is executed, not on install or require, refraining from running the binary mitigates immediate risk. Monitor the package's official repository and vendor advisories for updates or patches. Consider removing the package from systems where it is not essential. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13615
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a77432cbf8831d539b460ad
Added to database: 08/08/2026, 14:54:36 UTC
Last enriched: 08/08/2026, 15:39:20 UTC
Last updated: 08/09/2026, 00:44:07 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.