Malicious code in @aster110/cc2wechat (npm)
The @aster110/cc2wechat npm package version 5.1.0 runs a daemon that polls Tencent's iLink Bot API for WeChat messages and forwards them to a locally hosted AI agent with all safety and sandbox restrictions disabled. This setup allows any sender of a WeChat message to execute arbitrary shell and filesystem commands on the host machine running the daemon. The remote shell capability activates only when the daemon is started via the CLI, not during installation or import.
AI Analysis
Technical Summary
The @aster110/cc2wechat package (version 5.1.0) implements a daemon that long-polls Tencent's iLink Bot API for incoming WeChat messages. Each message is forwarded to a local AI command-line interface configured with disabled approval and sandbox gates, allowing automatic execution of shell commands and filesystem operations without user prompts. The daemon uses tmux or an alternative backend to inject commands into the AI session. This design creates a remote shell attack surface: any party able to send a WeChat message to the linked account can execute arbitrary commands on the host machine. The remote shell surface is exposed only when the daemon is explicitly started via the CLI command `cc2wechat start`.
Potential Impact
An attacker who can send messages to the linked WeChat account can execute arbitrary shell and filesystem commands on the host machine running the daemon. This effectively grants full host control to the attacker, posing a critical security risk. The package README documents that it requires a disposable VM due to this full-host access risk. There is no indication of active exploitation in the wild.
Mitigation Recommendations
No official patch or fix is currently documented. Operators should avoid running the daemon unless in a fully isolated disposable virtual machine environment as recommended by the package documentation. Do not run the daemon on production or sensitive systems. Since the remote shell surface is only exposed when the daemon is started, avoid executing the `cc2wechat start` command unless absolutely necessary and in a secure environment. Monitor for updates or advisories from the package maintainer for any future remediation.
Malicious code in @aster110/cc2wechat (npm)
Description
The @aster110/cc2wechat npm package version 5.1.0 runs a daemon that polls Tencent's iLink Bot API for WeChat messages and forwards them to a locally hosted AI agent with all safety and sandbox restrictions disabled. This setup allows any sender of a WeChat message to execute arbitrary shell and filesystem commands on the host machine running the daemon. The remote shell capability activates only when the daemon is started via the CLI, not during installation or import.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @aster110/cc2wechat package (version 5.1.0) implements a daemon that long-polls Tencent's iLink Bot API for incoming WeChat messages. Each message is forwarded to a local AI command-line interface configured with disabled approval and sandbox gates, allowing automatic execution of shell commands and filesystem operations without user prompts. The daemon uses tmux or an alternative backend to inject commands into the AI session. This design creates a remote shell attack surface: any party able to send a WeChat message to the linked account can execute arbitrary commands on the host machine. The remote shell surface is exposed only when the daemon is explicitly started via the CLI command `cc2wechat start`.
Potential Impact
An attacker who can send messages to the linked WeChat account can execute arbitrary shell and filesystem commands on the host machine running the daemon. This effectively grants full host control to the attacker, posing a critical security risk. The package README documents that it requires a disposable VM due to this full-host access risk. There is no indication of active exploitation in the wild.
Mitigation Recommendations
No official patch or fix is currently documented. Operators should avoid running the daemon unless in a fully isolated disposable virtual machine environment as recommended by the package documentation. Do not run the daemon on production or sensitive systems. Since the remote shell surface is only exposed when the daemon is started, avoid executing the `cc2wechat start` command unless absolutely necessary and in a secure environment. Monitor for updates or advisories from the package maintainer for any future remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13520
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a75f709bf8831d53984ec99
Added to database: 08/07/2026, 15:17:29 UTC
Last enriched: 08/07/2026, 15:22:36 UTC
Last updated: 09/22/2026, 01:41:45 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.