Malicious code in @aster110/cc2wechat (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a22dda7bf5c10da8b67b359d665b133709826bdebbd6632fc0fcf04551f1efac) The package runs a daemon that long-polls Tencent's iLink Bot API (ilinkai.weixin.qq.com) for incoming WeChat messages and forwards each message body into a locally hosted AI agent that is spawned with all approval and sandbox gates disabled. Specifically, TmuxDelivery.deliver writes the message text (`sendToSession(sessionName, "[微信...] " + ctx.text)`) into a tmux session whose command line is `CC2WECHAT_CONTEXT=... claude --dangerously-skip-permissions`, using tmux `load-buffer` + `paste-buffer` + `send-keys Enter` to submit the input. An alternative backend spawns `codex exec --json --dangerously-bypass-approvals-and-sandbox` and feeds the same WeChat message stream into it. Because these AI CLIs are configured to auto-execute shell commands and filesystem operations without prompts when safety flags are disabled, any party able to send a WeChat message to the linked account can drive arbitrary shell and file operations on the machine running the daemon. The tool is documented in the README as full-host access requiring a disposable VM. The startup entry point is a `bin` CLI (`cc2wechat start`), so the remote-shell surface materializes when the operator launches the daemon rather than on `npm install` or `require()`.
Malicious code in @aster110/cc2wechat (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a22dda7bf5c10da8b67b359d665b133709826bdebbd6632fc0fcf04551f1efac) The package runs a daemon that long-polls Tencent's iLink Bot API (ilinkai.weixin.qq.com) for incoming WeChat messages and forwards each message body into a locally hosted AI agent that is spawned with all approval and sandbox gates disabled. Specifically, TmuxDelivery.deliver writes the message text (`sendToSession(sessionName, "[微信...] " + ctx.text)`) into a tmux session whose command line is `CC2WECHAT_CONTEXT=... claude --dangerously-skip-permissions`, using tmux `load-buffer` + `paste-buffer` + `send-keys Enter` to submit the input. An alternative backend spawns `codex exec --json --dangerously-bypass-approvals-and-sandbox` and feeds the same WeChat message stream into it. Because these AI CLIs are configured to auto-execute shell commands and filesystem operations without prompts when safety flags are disabled, any party able to send a WeChat message to the linked account can drive arbitrary shell and file operations on the machine running the daemon. The tool is documented in the README as full-host access requiring a disposable VM. The startup entry point is a `bin` CLI (`cc2wechat start`), so the remote-shell surface materializes when the operator launches the daemon rather than on `npm install` or `require()`.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13520
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75f709bf8831d53984ec99
Added to database: 08/07/2026, 15:17:29 UTC
Last updated: 08/07/2026, 15:17:29 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.