Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @whalent/agent-core (npm)

0
Critical
Published: 07/16/2026 (07/16/2026, 18:41:02 UTC)
Source: GCVE Database
Product: @whalent/agent-core

Description

The @whalent/agent-core npm package contains malicious code that establishes a WebSocket connection to a hardcoded remote gateway, enabling the operator to execute arbitrary commands on any host running the package. The package supports remote code updates from the same gateway without visible version or signature verification. It also exfiltrates AI-provider session identifiers and API keys to the attacker-controlled host. The code is heavily obfuscated to evade casual inspection. This affects specific versions of the package and no official patch or fix is currently documented.

Affected software

npmghsa
@whalent/agent-core
Affected versions
=0.3.230=0.3.231=0.3.232=0.3.233=0.3.254

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:06:57 UTC

Technical Analysis

The @whalent/agent-core package (versions =0.3.230, =0.3.231, =0.3.232, =0.3.233, =0.3.254) includes a bundled runtime that opens a WebSocket connection to wss://memory.whalent.com/gw/sdk/ws. This connection allows the remote gateway operator to control a pseudo-terminal (PTY) on the host by sending commands, effectively enabling arbitrary command execution. The package's README indicates that the runtime can be remotely upgraded by the same gateway without any visible version or signature pinning, creating a covert remote code update channel. Additionally, the runtime collects AI-provider session data and API keys from local configuration files and sends them to the attacker-controlled endpoint. The entire 4.8 MB runtime is obfuscated using string-array indirection and numerous decoder wrappers to conceal its malicious behavior.

Potential Impact

Hosts running affected versions of @whalent/agent-core are at risk of arbitrary remote code execution by the attacker controlling the hardcoded WebSocket gateway. This allows full command execution capabilities on the compromised system. Furthermore, sensitive AI-provider session identifiers and API keys stored locally may be exfiltrated to the attacker, potentially compromising user accounts and data. The remote code update mechanism enables the attacker to modify or replace the installed runtime without detection, prolonging and escalating the compromise.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package. Users should immediately remove the affected versions of @whalent/agent-core from their environments and avoid installing or running this package. Monitor for any network connections to wss://memory.whalent.com and related domains and investigate any signs of compromise. Since the package supports remote code updates from an attacker-controlled endpoint, any system that has run this package should be considered compromised and undergo thorough incident response and remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10722
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735742bf8831d539158e55

Added to database: 08/05/2026, 15:31:14 UTC

Last enriched: 08/05/2026, 17:06:57 UTC

Last updated: 08/05/2026, 17:06:57 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses