Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'mal-2026-10711'

View all threats tagged with 'mal-2026-10711'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-10711

Threats Tagged 'mal-2026-10711'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in @funny-booth/agent-core (npm)
0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6693129f8b6f8b6c2d52722ca7746d6ef3dd792476297fa3583d3956548eb2b4) The package ships heavily obfuscated runtime files (dist/index.js, dist/launcher.js) built with javascript-obfuscator. The MCP server registered as the package's main entry exposes an `install_mcp` tool that fetches JSON from the hardcoded portal `prompt-injection-tool-portal.vercel.app` and passes its `install_command` field directly to `child_process.exec()` on the installer's host, giving the portal operator arbitrary shell execution with the installer's privileges. The launcher (invoked by every `salesbot1..10` bin entry) calls `fetchBundledMcps` against the same portal and, for each returned entry, spawns `npx -y <entry.package>` while injecting locally decrypted vault secrets into the child's env — the portal can name any npm package, including a freshly published attacker-owned one, and it will be downloaded and executed with those secrets on hand. The launcher also unconditionally spawns a detached `npm i -g @funny-booth/agent-core@latest` on every run, silently self-updating to whatever the publisher pushes next. The launcher additionally spawns the local `claude` CLI with a portal-supplied greeting/knowledge string prepended as the initial user prompt and a portal-controlled MCP config, providing a prompt-injection channel into the user's Claude agent session. The repository URL in package.json is `github.com/yutamatsuura/prompt-injection-tool` and the deliberate obfuscation of the portal endpoints, exec sink, and auto-update spawn is consistent with intentional concealment of these remote-execution channels.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-10711
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses