Malicious code in gpt-terminal-cli (npm)
The gpt-terminal-cli npm package version 1.0.0 contains malicious code that installs a persistent background daemon implant. This implant connects to a hardcoded command-and-control (C2) server, enabling a wide range of attacker capabilities including remote shell access, credential theft, keylogging, file exfiltration, privilege escalation, and anti-forensics. The implant uses advanced techniques such as self-healing persistence with multiple respawns, runtime C2 rotation via DNS TXT polling, and AMSI bypass on Windows PowerShell commands.
AI Analysis
Technical Summary
The gpt-terminal-cli package (version 1.0.0) masquerades as an AI chat CLI but executes a post-install script that launches a detached implant daemon. This implant maintains persistence by respawning up to 50 times if terminated and communicates with a hardcoded C2 server at http://13.60.13.215:7771 using an AES-256-GCM encrypted and HMAC-signed protocol. It supports multiple malicious operations including reverse PTY shell access, credential theft, clipboard and keylogging data collection, file exfiltration, lateral movement, privilege escalation, and anti-forensics. The implant dynamically updates its C2 endpoint and encryption keys by polling DNS TXT records every 30 minutes, enabling infrastructure agility without package updates. On Windows, it bypasses AMSI protections by injecting a reflection stub into PowerShell invocations.
Potential Impact
This malicious package enables attackers to gain persistent remote access to infected systems, steal sensitive credentials and data, monitor user activity via keylogging and clipboard capture, exfiltrate files, escalate privileges, move laterally within networks, and evade detection through anti-forensics techniques. The implant's self-healing and dynamic C2 rotation capabilities increase its resilience and complicate incident response.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately uninstall version 1.0.0 of gpt-terminal-cli and avoid installing this package. Conduct thorough system scans for the implant and related artifacts if this package was installed. Monitor network traffic for connections to the known C2 IP (13.60.13.215) and related domains. Since this is a malicious package, remediation involves removal and incident response rather than patching. Check vendor or repository advisories for updates or warnings.
Malicious code in gpt-terminal-cli (npm)
Description
The gpt-terminal-cli npm package version 1.0.0 contains malicious code that installs a persistent background daemon implant. This implant connects to a hardcoded command-and-control (C2) server, enabling a wide range of attacker capabilities including remote shell access, credential theft, keylogging, file exfiltration, privilege escalation, and anti-forensics. The implant uses advanced techniques such as self-healing persistence with multiple respawns, runtime C2 rotation via DNS TXT polling, and AMSI bypass on Windows PowerShell commands.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The gpt-terminal-cli package (version 1.0.0) masquerades as an AI chat CLI but executes a post-install script that launches a detached implant daemon. This implant maintains persistence by respawning up to 50 times if terminated and communicates with a hardcoded C2 server at http://13.60.13.215:7771 using an AES-256-GCM encrypted and HMAC-signed protocol. It supports multiple malicious operations including reverse PTY shell access, credential theft, clipboard and keylogging data collection, file exfiltration, lateral movement, privilege escalation, and anti-forensics. The implant dynamically updates its C2 endpoint and encryption keys by polling DNS TXT records every 30 minutes, enabling infrastructure agility without package updates. On Windows, it bypasses AMSI protections by injecting a reflection stub into PowerShell invocations.
Potential Impact
This malicious package enables attackers to gain persistent remote access to infected systems, steal sensitive credentials and data, monitor user activity via keylogging and clipboard capture, exfiltrate files, escalate privileges, move laterally within networks, and evade detection through anti-forensics techniques. The implant's self-healing and dynamic C2 rotation capabilities increase its resilience and complicate incident response.
Defensive Guidance
No official patch or remediation is currently available. Users should immediately uninstall version 1.0.0 of gpt-terminal-cli and avoid installing this package. Conduct thorough system scans for the implant and related artifacts if this package was installed. Monitor network traffic for connections to the known C2 IP (13.60.13.215) and related domains. Since this is a malicious package, remediation involves removal and incident response rather than patching. Check vendor or repository advisories for updates or warnings.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13447
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75744dbf8831d539d9b056
Added to database: 08/07/2026, 05:59:41 UTC
Last enriched: 08/07/2026, 06:12:30 UTC
Last updated: 08/07/2026, 06:13:04 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.