Skip to main content

Malicious code in @aster110/cc2wechat (npm)

0
Critical
Published: 08/07/2026 (08/07/2026, 12:43:35 UTC)
Source: GCVE Database
Product: @aster110/cc2wechat

Description

The @aster110/cc2wechat npm package version 5.1.0 runs a daemon that polls Tencent's iLink Bot API for WeChat messages and forwards them to a locally hosted AI agent with all safety and sandbox restrictions disabled. This setup allows any sender of a WeChat message to execute arbitrary shell and filesystem commands on the host machine running the daemon. The remote shell capability activates only when the daemon is started via the CLI, not during installation or import.

Affected software

npmghsa
@aster110/cc2wechat
Affected versions
=5.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 15:22:36 UTC

Technical Analysis

The @aster110/cc2wechat package (version 5.1.0) implements a daemon that long-polls Tencent's iLink Bot API for incoming WeChat messages. Each message is forwarded to a local AI command-line interface configured with disabled approval and sandbox gates, allowing automatic execution of shell commands and filesystem operations without user prompts. The daemon uses tmux or an alternative backend to inject commands into the AI session. This design creates a remote shell attack surface: any party able to send a WeChat message to the linked account can execute arbitrary commands on the host machine. The remote shell surface is exposed only when the daemon is explicitly started via the CLI command `cc2wechat start`.

Potential Impact

An attacker who can send messages to the linked WeChat account can execute arbitrary shell and filesystem commands on the host machine running the daemon. This effectively grants full host control to the attacker, posing a critical security risk. The package README documents that it requires a disposable VM due to this full-host access risk. There is no indication of active exploitation in the wild.

Mitigation Recommendations

No official patch or fix is currently documented. Operators should avoid running the daemon unless in a fully isolated disposable virtual machine environment as recommended by the package documentation. Do not run the daemon on production or sensitive systems. Since the remote shell surface is only exposed when the daemon is started, avoid executing the `cc2wechat start` command unless absolutely necessary and in a secure environment. Monitor for updates or advisories from the package maintainer for any future remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13520
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a75f709bf8831d53984ec99

Added to database: 08/07/2026, 15:17:29 UTC

Last enriched: 08/07/2026, 15:22:36 UTC

Last updated: 09/22/2026, 01:41:45 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses