Malicious code in @whalent/agent-core (npm)
The @whalent/agent-core npm package contains malicious code that establishes a WebSocket connection to a hardcoded remote gateway, enabling the operator to execute arbitrary commands on any host running the package. The package supports remote code updates from the same gateway without visible version or signature verification. It also exfiltrates AI-provider session identifiers and API keys to the attacker-controlled host. The code is heavily obfuscated to evade casual inspection. This affects specific versions of the package and no official patch or fix is currently documented.
AI Analysis
Technical Summary
The @whalent/agent-core package (versions =0.3.230, =0.3.231, =0.3.232, =0.3.233, =0.3.254) includes a bundled runtime that opens a WebSocket connection to wss://memory.whalent.com/gw/sdk/ws. This connection allows the remote gateway operator to control a pseudo-terminal (PTY) on the host by sending commands, effectively enabling arbitrary command execution. The package's README indicates that the runtime can be remotely upgraded by the same gateway without any visible version or signature pinning, creating a covert remote code update channel. Additionally, the runtime collects AI-provider session data and API keys from local configuration files and sends them to the attacker-controlled endpoint. The entire 4.8 MB runtime is obfuscated using string-array indirection and numerous decoder wrappers to conceal its malicious behavior.
Potential Impact
Hosts running affected versions of @whalent/agent-core are at risk of arbitrary remote code execution by the attacker controlling the hardcoded WebSocket gateway. This allows full command execution capabilities on the compromised system. Furthermore, sensitive AI-provider session identifiers and API keys stored locally may be exfiltrated to the attacker, potentially compromising user accounts and data. The remote code update mechanism enables the attacker to modify or replace the installed runtime without detection, prolonging and escalating the compromise.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately remove the affected versions of @whalent/agent-core from their environments and avoid installing or running this package. Monitor for any network connections to wss://memory.whalent.com and related domains and investigate any signs of compromise. Since the package supports remote code updates from an attacker-controlled endpoint, any system that has run this package should be considered compromised and undergo thorough incident response and remediation.
Malicious code in @whalent/agent-core (npm)
Description
The @whalent/agent-core npm package contains malicious code that establishes a WebSocket connection to a hardcoded remote gateway, enabling the operator to execute arbitrary commands on any host running the package. The package supports remote code updates from the same gateway without visible version or signature verification. It also exfiltrates AI-provider session identifiers and API keys to the attacker-controlled host. The code is heavily obfuscated to evade casual inspection. This affects specific versions of the package and no official patch or fix is currently documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @whalent/agent-core package (versions =0.3.230, =0.3.231, =0.3.232, =0.3.233, =0.3.254) includes a bundled runtime that opens a WebSocket connection to wss://memory.whalent.com/gw/sdk/ws. This connection allows the remote gateway operator to control a pseudo-terminal (PTY) on the host by sending commands, effectively enabling arbitrary command execution. The package's README indicates that the runtime can be remotely upgraded by the same gateway without any visible version or signature pinning, creating a covert remote code update channel. Additionally, the runtime collects AI-provider session data and API keys from local configuration files and sends them to the attacker-controlled endpoint. The entire 4.8 MB runtime is obfuscated using string-array indirection and numerous decoder wrappers to conceal its malicious behavior.
Potential Impact
Hosts running affected versions of @whalent/agent-core are at risk of arbitrary remote code execution by the attacker controlling the hardcoded WebSocket gateway. This allows full command execution capabilities on the compromised system. Furthermore, sensitive AI-provider session identifiers and API keys stored locally may be exfiltrated to the attacker, potentially compromising user accounts and data. The remote code update mechanism enables the attacker to modify or replace the installed runtime without detection, prolonging and escalating the compromise.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately remove the affected versions of @whalent/agent-core from their environments and avoid installing or running this package. Monitor for any network connections to wss://memory.whalent.com and related domains and investigate any signs of compromise. Since the package supports remote code updates from an attacker-controlled endpoint, any system that has run this package should be considered compromised and undergo thorough incident response and remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10722
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735742bf8831d539158e55
Added to database: 08/05/2026, 15:31:14 UTC
Last enriched: 08/05/2026, 17:06:57 UTC
Last updated: 08/05/2026, 17:06:57 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.