Malicious code in chatcc-agent (npm)
The chatcc-agent npm package runs a daemon that connects to Tencent Cloud IM and accepts remote commands via WebSocket messages. These commands can spawn or write to a local shell or PTY on the host machine, effectively providing a remote shell access channel. Access is controlled by JWT and paired-client authentication, but the design inherently exposes a remote command execution surface. The npm install script only performs local native builds and does not fetch remote content. Version 0.8.24 is affected.
AI Analysis
Technical Summary
chatcc-agent version 0.8.24 runs a daemon connecting to Tencent Cloud IM as a WebSocket client. It processes inbound peer messages of types 'terminal_command', 'terminal_input', and 'terminal_pty_*' as instructions to spawn or write to a local shell or PTY on the host. The function _handleAdvancedCommand invokes pty.spawn with the remote command string, and handleInput forwards peer-supplied bytes to the process's stdin. This creates a network-accessible remote-controlled command execution channel on the host machine. Although access is gated by JWT and paired-client authentication, the remote shell capability exists by design. The npm install script only performs local compilation and does not retrieve or execute remote code.
Potential Impact
An attacker who can authenticate via the JWT or paired-client mechanism can execute arbitrary commands on the host machine running chatcc-agent 0.8.24. This provides full remote shell access, which could lead to complete system compromise. The risk depends on the security of the authentication mechanism and exposure of the WebSocket interface.
Mitigation Recommendations
No official patch or fix is currently documented. Users should carefully evaluate the trustworthiness of the chatcc-agent package and its deployment environment. Restrict network access to the WebSocket interface and ensure strong authentication controls are in place. Monitor for unauthorized access attempts. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in chatcc-agent (npm)
Description
The chatcc-agent npm package runs a daemon that connects to Tencent Cloud IM and accepts remote commands via WebSocket messages. These commands can spawn or write to a local shell or PTY on the host machine, effectively providing a remote shell access channel. Access is controlled by JWT and paired-client authentication, but the design inherently exposes a remote command execution surface. The npm install script only performs local native builds and does not fetch remote content. Version 0.8.24 is affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
chatcc-agent version 0.8.24 runs a daemon connecting to Tencent Cloud IM as a WebSocket client. It processes inbound peer messages of types 'terminal_command', 'terminal_input', and 'terminal_pty_*' as instructions to spawn or write to a local shell or PTY on the host. The function _handleAdvancedCommand invokes pty.spawn with the remote command string, and handleInput forwards peer-supplied bytes to the process's stdin. This creates a network-accessible remote-controlled command execution channel on the host machine. Although access is gated by JWT and paired-client authentication, the remote shell capability exists by design. The npm install script only performs local compilation and does not retrieve or execute remote code.
Potential Impact
An attacker who can authenticate via the JWT or paired-client mechanism can execute arbitrary commands on the host machine running chatcc-agent 0.8.24. This provides full remote shell access, which could lead to complete system compromise. The risk depends on the security of the authentication mechanism and exposure of the WebSocket interface.
Mitigation Recommendations
No official patch or fix is currently documented. Users should carefully evaluate the trustworthiness of the chatcc-agent package and its deployment environment. Restrict network access to the WebSocket interface and ensure strong authentication controls are in place. Monitor for unauthorized access attempts. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13259
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738520bf8831d5394ef8fc
Added to database: 08/05/2026, 18:46:56 UTC
Last enriched: 08/05/2026, 23:00:32 UTC
Last updated: 08/05/2026, 23:00:32 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.