Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in agenthub-ai (npm)

0
Critical
Published: 08/07/2026 (08/07/2026, 16:34:12 UTC)
Source: GCVE Database
Product: agenthub-ai

Description

The agenthub-ai npm package runs a persistent daemon that connects to a hardcoded WebSocket server controlled by the package maintainer or potentially an attacker who compromises that server. This daemon can execute server-supplied commands with broad file system access and spawn subprocesses, enabling full host control. It also supports a remote update mechanism that can force the installation of new code versions. Additionally, the package redirects native bindings to a placeholder package, which could be replaced later with malicious payloads. The daemon activates only when the package's binary is run, not during installation or import.

Affected software

npmghsa
agenthub-ai
Affected versions
=0.20.1=0.20.2=0.20.4=0.20.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 15:39:20 UTC

Technical Analysis

The agenthub-ai npm package versions 0.20.1, 0.20.2, 0.20.3, and 0.20.4 include a persistent daemon that opens a WebSocket connection to a hardcoded production endpoint (wss://agenthub-agent.fyenet.com). This connection allows the server to send commands that read, write, and search files on the host machine and spawn the local Claude Agent CLI with arbitrary prompts. The daemon's default permissions bypass restrictions, granting extensive control to the server operator or any party who compromises it. A documented 'update' action enables the server to stop the daemon, run 'npm install' to fetch the latest agenthub-ai version, and restart the daemon, effectively allowing forced remote code execution under the package's name. The package.json uses overrides to replace native subpackages with a stub package ([email protected]), which could be republished with malicious payloads, affecting all installers. The daemon only runs when the package's binary is executed, not during installation or when required as a module.

Potential Impact

Any party controlling the WebSocket server can execute arbitrary code with full host privileges on machines running the agenthub-ai daemon. This includes reading, writing, and searching files and spawning subprocesses with arbitrary commands. The remote update mechanism allows forced installation of new malicious code versions, escalating the risk of persistent compromise. The override of native bindings to a placeholder package introduces supply chain risk, as a malicious republish could affect all users of the package. This results in a high risk of full system compromise for users running the daemon.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should avoid running the agenthub-ai package binary to prevent the daemon from starting. Since the daemon only activates when the binary is executed, not on install or require, refraining from running the binary mitigates immediate risk. Monitor the package's official repository and vendor advisories for updates or patches. Consider removing the package from systems where it is not essential. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13615
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a77432cbf8831d539b460ad

Added to database: 08/08/2026, 14:54:36 UTC

Last enriched: 08/08/2026, 15:39:20 UTC

Last updated: 08/09/2026, 00:44:07 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses