Skip to main content

Malicious code in @guangnao/claude-cli (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 15:52:10 UTC)
Source: GCVE Database
Product: @guangnao/claude-cli

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b9276dba65fd393d94c5beb06122b1297994c96bda03d940f34fcc59016e4c5b) The bundled CLI at bin/claude-cli.js hardcodes a hub endpoint https://hub.client-llm.com that is concealed behind a bespoke base64+XOR decoder (function _deHub, XOR key 'gnP2p!7xQ'). The decoder is used exactly once, to reconstruct this single URL; no other strings in the bundle use it. On `claude-cli start`, this hidden hub is added by default to the active hub list (opt-out only, undocumented), while the README presents hub participation as an opt-in feature the user manually configures. Once started, the CLI opens a WebSocket to <hub>/node, and on receiving {t:"job", id, body} messages it POSTs the remote-supplied body to the installer's local http://127.0.0.1:<port>/v1/messages endpoint using the local API key (x-api-key header) and streams the response back over the WebSocket. In default mode this dispatches a `claude -p` child process on the installer's machine driven by attacker-controlled prompts, consuming the installer's paid Anthropic subscription and, given agentic/tool-enabled Claude sessions, exposing remote-controlled execution paths on the installer's host. The targeted obfuscation of the destination URL, the mismatch between documented opt-in behavior and actual default-on enrollment, and the remote job-dispatch channel together constitute a backdoor combined with silent relay of the installer's Claude credentials and quota.

Affected software

npmghsa
@guangnao/claude-cli
Affected versions
=1.0.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 23:17:05 UTC

Technical Analysis

The @guangnao/claude-cli package (version 1.0.5) includes malicious functionality where the CLI connects to a hardcoded, obfuscated remote WebSocket server (wss://hub.client-llm.com/node). It uploads sensitive authentication credentials stored locally (~/.claude/.credentials.json and macOS keychain entries) to this server. The remote operator can send control frames to the CLI, which forwards them to the local Claude API endpoint, effectively using the installer's paid Claude subscription remotely. The entire credential exfiltration and remote control mechanism is hidden from users and not documented in the README or environment variables, allowing the attacker to impersonate the user and leverage their subscription without consent.

Potential Impact

An attacker controlling hub.client-llm.com can impersonate the user of the @guangnao/claude-cli package by using stolen authentication credentials. This enables unauthorized access to the victim's paid Claude subscription, potentially incurring costs or misuse of the service. The victim is unaware of the credential theft and remote control due to the obfuscation and lack of disclosure, leading to a significant breach of confidentiality and potential financial impact.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately discontinue use of @guangnao/claude-cli version 1.0.5 and remove it from their systems. Monitor for updates from the package maintainer or npm advisory for any official fixes. Until a fix is available, avoid installing or running this package to prevent credential theft and unauthorized subscription use.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13209
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a73851fbf8831d5394ef86a

Added to database: 08/05/2026, 18:46:55 UTC

Last enriched: 08/05/2026, 23:17:05 UTC

Last updated: 09/12/2026, 11:09:15 UTC

Views: 20

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses