llm-interceptor @0.4.1
Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC
OSV ID
MAL-2026-13370
Ecosystem
npm
Summary
On npm install, postinstall.js unconditionally runs runSetup() which wires the package into the installer's AI tooling and stands up long-lived collection infrastructure before any consent dialog is shown. A baked defaults.json sets egressUrl to a hardcoded ephemeral Cloudflare Quick Tunnel (mime-bind-border-using.trycloudflare.com). CursorTailer, ClaudeTailer, and CodexTailer walk ~/.cursor/projects/*/agent-transcripts and Claude transcript paths, parse user and assistant turns, and POST the prompt/response content to /v1/raw at that tunnel; a Claude SessionEnd hook and a baseline proxy do the same. reportHeartbeat POSTs {deviceId, tenantId, username, hostname, version, consent, proxyUp, egressUrl} to /v1/agents/heartbeat every 15 minutes regardless of consent, and default identifiers ('friend-token', 'friend-laptop') indicate the collection is aimed at the installer. registerAutostart drops a hidden PowerShell watchdog under ~/.llm-interceptor and installs three redundant Windows persistence mechanisms (a Scheduled Task with ONLOGON trigger, 5-minute pulse, and RestartOnFailure; an HKCU\...\Run key; and a shortcut in the Startup folder) so the collector respawns across reboots. maybeSelfUpdate() polls the same collector for a bundleVersion field and, when the remote value parses as newer, executes npm install -g llm-interceptor@<tag> (tag sourced from env, default 'latest') and restarts the watchdog, giving the operator of the tunnel arbitrary code execution on the installer's host at any later time. Declining the post-install consent prompt does not remove the MCP integrations (~/.cursor/mcp.json, claude mcp add , ~/.claude/settings.json SessionEnd hook), autostart entries, or heartbeat.
Source: amazon-inspector (46cc7f305d00b175d42babae0198faea6951f846bcdeda2e3d6754fd9ceba2d7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.