Malicious code in claude-team-tracker (npm)
The claude-team-tracker npm package versions 1.2.0, 1.2.1, and 1.2.2 contain malicious code that installs a persistent backdoor on affected systems. Upon installation, it bypasses npm's standard input/output to spawn a setup process that installs persistence mechanisms via cron, systemd user services, or macOS LaunchAgents. This backdoor maintains a long-polling daemon that connects to a remote server to receive commands, including the ability to execute arbitrary npm package installations system-wide, enabling remote code execution controlled by the attacker. Additionally, the package exfiltrates sensitive Anthropic OAuth user identity and organizational information to the attacker's server. This combination of persistent remote code execution and identity data exfiltration constitutes a severe security threat.
AI Analysis
Technical Summary
The claude-team-tracker npm package (versions 1.2.0, 1.2.1, and 1.2.2) contains malicious post-installation code that opens /dev/tty to bypass npm stdio, spawning a setup process that installs persistence via cron, systemd user services with loginctl enable-linger on Linux, or LaunchAgent with KeepAlive on macOS. The installed daemon long-polls tracker.clawodoo.com/api/commands, executing server-supplied npm install commands globally on the host, providing a stable remote code push channel. Separately, the package reads the user's Anthropic OAuth token from ~/.claude/.credentials.json, retrieves detailed user and organization profile information via the Anthropic API, and reports this data along with machine identifiers to the attacker's server. This installer-side backdoor enables persistent remote code execution and credential-adjacent identity disclosure, bypassing the package's purported team usage tracking functionality.
Potential Impact
This malicious package enables attackers to maintain persistent remote code execution on affected systems, allowing them to install arbitrary npm packages globally at will. It also leaks sensitive user identity and organizational information linked to the Anthropic OAuth token, potentially compromising user privacy and organizational security. The persistence mechanisms ensure the backdoor survives reboots and user logouts, increasing the difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately uninstall claude-team-tracker versions 1.2.0, 1.2.1, and 1.2.2 and remove any persistence mechanisms installed by it (cron jobs, systemd user services with linger enabled, macOS LaunchAgents). Review and revoke any compromised Anthropic OAuth tokens and monitor for unauthorized npm package installations. Avoid installing packages from untrusted sources and verify package integrity before installation. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Malicious code in claude-team-tracker (npm)
Description
The claude-team-tracker npm package versions 1.2.0, 1.2.1, and 1.2.2 contain malicious code that installs a persistent backdoor on affected systems. Upon installation, it bypasses npm's standard input/output to spawn a setup process that installs persistence mechanisms via cron, systemd user services, or macOS LaunchAgents. This backdoor maintains a long-polling daemon that connects to a remote server to receive commands, including the ability to execute arbitrary npm package installations system-wide, enabling remote code execution controlled by the attacker. Additionally, the package exfiltrates sensitive Anthropic OAuth user identity and organizational information to the attacker's server. This combination of persistent remote code execution and identity data exfiltration constitutes a severe security threat.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The claude-team-tracker npm package (versions 1.2.0, 1.2.1, and 1.2.2) contains malicious post-installation code that opens /dev/tty to bypass npm stdio, spawning a setup process that installs persistence via cron, systemd user services with loginctl enable-linger on Linux, or LaunchAgent with KeepAlive on macOS. The installed daemon long-polls tracker.clawodoo.com/api/commands, executing server-supplied npm install commands globally on the host, providing a stable remote code push channel. Separately, the package reads the user's Anthropic OAuth token from ~/.claude/.credentials.json, retrieves detailed user and organization profile information via the Anthropic API, and reports this data along with machine identifiers to the attacker's server. This installer-side backdoor enables persistent remote code execution and credential-adjacent identity disclosure, bypassing the package's purported team usage tracking functionality.
Potential Impact
This malicious package enables attackers to maintain persistent remote code execution on affected systems, allowing them to install arbitrary npm packages globally at will. It also leaks sensitive user identity and organizational information linked to the Anthropic OAuth token, potentially compromising user privacy and organizational security. The persistence mechanisms ensure the backdoor survives reboots and user logouts, increasing the difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately uninstall claude-team-tracker versions 1.2.0, 1.2.1, and 1.2.2 and remove any persistence mechanisms installed by it (cron jobs, systemd user services with linger enabled, macOS LaunchAgents). Review and revoke any compromised Anthropic OAuth tokens and monitor for unauthorized npm package installations. Avoid installing packages from untrusted sources and verify package integrity before installation. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10473
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ffa268715ace432f7348
Added to database: 07/14/2026, 09:21:38 UTC
Last enriched: 07/14/2026, 09:54:14 UTC
Last updated: 07/30/2026, 00:47:15 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.