Malicious code in @guangnao/claude-cli (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b9276dba65fd393d94c5beb06122b1297994c96bda03d940f34fcc59016e4c5b) The bundled CLI at bin/claude-cli.js hardcodes a hub endpoint https://hub.client-llm.com that is concealed behind a bespoke base64+XOR decoder (function _deHub, XOR key 'gnP2p!7xQ'). The decoder is used exactly once, to reconstruct this single URL; no other strings in the bundle use it. On `claude-cli start`, this hidden hub is added by default to the active hub list (opt-out only, undocumented), while the README presents hub participation as an opt-in feature the user manually configures. Once started, the CLI opens a WebSocket to <hub>/node, and on receiving {t:"job", id, body} messages it POSTs the remote-supplied body to the installer's local http://127.0.0.1:<port>/v1/messages endpoint using the local API key (x-api-key header) and streams the response back over the WebSocket. In default mode this dispatches a `claude -p` child process on the installer's machine driven by attacker-controlled prompts, consuming the installer's paid Anthropic subscription and, given agentic/tool-enabled Claude sessions, exposing remote-controlled execution paths on the installer's host. The targeted obfuscation of the destination URL, the mismatch between documented opt-in behavior and actual default-on enrollment, and the remote job-dispatch channel together constitute a backdoor combined with silent relay of the installer's Claude credentials and quota.
AI Analysis
Technical Summary
The @guangnao/claude-cli package (version 1.0.5) includes malicious functionality where the CLI connects to a hardcoded, obfuscated remote WebSocket server (wss://hub.client-llm.com/node). It uploads sensitive authentication credentials stored locally (~/.claude/.credentials.json and macOS keychain entries) to this server. The remote operator can send control frames to the CLI, which forwards them to the local Claude API endpoint, effectively using the installer's paid Claude subscription remotely. The entire credential exfiltration and remote control mechanism is hidden from users and not documented in the README or environment variables, allowing the attacker to impersonate the user and leverage their subscription without consent.
Potential Impact
An attacker controlling hub.client-llm.com can impersonate the user of the @guangnao/claude-cli package by using stolen authentication credentials. This enables unauthorized access to the victim's paid Claude subscription, potentially incurring costs or misuse of the service. The victim is unaware of the credential theft and remote control due to the obfuscation and lack of disclosure, leading to a significant breach of confidentiality and potential financial impact.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately discontinue use of @guangnao/claude-cli version 1.0.5 and remove it from their systems. Monitor for updates from the package maintainer or npm advisory for any official fixes. Until a fix is available, avoid installing or running this package to prevent credential theft and unauthorized subscription use.
Malicious code in @guangnao/claude-cli (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b9276dba65fd393d94c5beb06122b1297994c96bda03d940f34fcc59016e4c5b) The bundled CLI at bin/claude-cli.js hardcodes a hub endpoint https://hub.client-llm.com that is concealed behind a bespoke base64+XOR decoder (function _deHub, XOR key 'gnP2p!7xQ'). The decoder is used exactly once, to reconstruct this single URL; no other strings in the bundle use it. On `claude-cli start`, this hidden hub is added by default to the active hub list (opt-out only, undocumented), while the README presents hub participation as an opt-in feature the user manually configures. Once started, the CLI opens a WebSocket to <hub>/node, and on receiving {t:"job", id, body} messages it POSTs the remote-supplied body to the installer's local http://127.0.0.1:<port>/v1/messages endpoint using the local API key (x-api-key header) and streams the response back over the WebSocket. In default mode this dispatches a `claude -p` child process on the installer's machine driven by attacker-controlled prompts, consuming the installer's paid Anthropic subscription and, given agentic/tool-enabled Claude sessions, exposing remote-controlled execution paths on the installer's host. The targeted obfuscation of the destination URL, the mismatch between documented opt-in behavior and actual default-on enrollment, and the remote job-dispatch channel together constitute a backdoor combined with silent relay of the installer's Claude credentials and quota.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @guangnao/claude-cli package (version 1.0.5) includes malicious functionality where the CLI connects to a hardcoded, obfuscated remote WebSocket server (wss://hub.client-llm.com/node). It uploads sensitive authentication credentials stored locally (~/.claude/.credentials.json and macOS keychain entries) to this server. The remote operator can send control frames to the CLI, which forwards them to the local Claude API endpoint, effectively using the installer's paid Claude subscription remotely. The entire credential exfiltration and remote control mechanism is hidden from users and not documented in the README or environment variables, allowing the attacker to impersonate the user and leverage their subscription without consent.
Potential Impact
An attacker controlling hub.client-llm.com can impersonate the user of the @guangnao/claude-cli package by using stolen authentication credentials. This enables unauthorized access to the victim's paid Claude subscription, potentially incurring costs or misuse of the service. The victim is unaware of the credential theft and remote control due to the obfuscation and lack of disclosure, leading to a significant breach of confidentiality and potential financial impact.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately discontinue use of @guangnao/claude-cli version 1.0.5 and remove it from their systems. Monitor for updates from the package maintainer or npm advisory for any official fixes. Until a fix is available, avoid installing or running this package to prevent credential theft and unauthorized subscription use.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13209
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73851fbf8831d5394ef86a
Added to database: 08/05/2026, 18:46:55 UTC
Last enriched: 08/05/2026, 23:17:05 UTC
Last updated: 09/12/2026, 11:09:15 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.