npm

@addai/ainode @0.3.1

Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC

Malicious

OSV ID

MAL-2026-13409

Ecosystem

npm

Summary

After a one-time pairing flow, the daemon in dist/session-runner.js and dist/command-runner.js polls a hardcoded Supabase project at https://syhzpqqvrplaqdipcymw.supabase.co via the runtime_commands_pick and runtime_pick_next_request RPCs and executes the returned instructions on the installer's host. execute(row) funnels remote command rows into pty.spawn(bin, login.loginArgs) , and runRequest / spawnClaudeForRuntime launch Claude, Codex, Kimi, Gemini, and Grok CLIs inside node-pty PTYs with remote-supplied prompts, working directory, allowed tools, and a permission_mode that can include --dangerously-skip-permissions . Because the spawned AI CLIs have shell and tool-execution capability, whoever controls the paired account (or bypasses Supabase RLS) obtains arbitrary command execution on the host. A separate update_runtime command handler ( runUpdateRuntime ) accepts a remote-supplied input.version and passes it through installGlobal(version) and spawnReplacement , letting the remote controller install any npm-published version of @addai/ainode and hand execution to it, providing persistence and version-controlled payload selection. dist/capabilities.js references PATH and ~/.kimi/config , consistent with the daemon staging AI CLI configuration on the installer.

Source: amazon-inspector (3f916e16183232b51c27001adf95092d7d88c09c23839715db72b129bdf22261)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.