MAL-2026-13370
Dashboard / Malicious Package / MAL-2026-13370
MAL-2026-13370
Summary: Malicious code in llm-interceptor (npm)
Details: Source: amazon-inspector (46cc7f305d00b175d42babae0198faea6951f846bcdeda2e3d6754fd9ceba2d7) On npm install, postinstall.js unconditionally runs runSetup() which wires the package into the installer's AI tooling and stands up long-lived collection infrastructure before any consent dialog is shown. A baked defaults.json sets egressUrl to a hardcoded ephemeral Cloudflare Quick Tunnel (mime-bind-border-using.trycloudflare.com). CursorTailer, ClaudeTailer, and CodexTailer walk ~/.cursor/projects/*/agent-transcripts and Claude transcript paths, parse user and assistant turns, and POST the prompt/response content to /v1/raw at that tunnel; a Claude SessionEnd hook and a baseline proxy do the same. reportHeartbeat POSTs {deviceId, tenantId, username, hostname, version, consent, proxyUp, egressUrl} to /v1/agents/heartbeat every 15 minutes regardless of consent, and default identifiers ('friend-token', 'friend-laptop') indicate the collection is aimed at the installer. registerAutostart drops a hidden PowerShell watchdog under ~/.llm-interceptor and installs three redundant Windows persistence mechanisms (a Scheduled Task with ONLOGON trigger, 5-minute pulse, and RestartOnFailure; an HKCU\...\Run key; and a shortcut in the Startup folder) so the collector respawns across reboots. maybeSelfUpdate() polls the same collector for a bundleVersion field and, when the remote value parses as newer, executes `npm install -g llm-interceptor@<tag>` (tag sourced from env, default 'latest') and restarts the watchdog, giving the operator of the tunnel arbitrary code execution on the installer's host at any later time. Declining the post-install consent prompt does not remove the MCP integrations (~/.cursor/mcp.json, `claude mcp add`, ~/.claude/settings.json SessionEnd hook), autostart entries, or heartbeat.
References: https://www.npmjs.com/package/llm-interceptor/v/0.3.0, https://www.npmjs.com/package/llm-interceptor/v/0.3.1, https://www.npmjs.com/package/llm-interceptor/v/0.3.4, https://www.npmjs.com/package/llm-interceptor/v/0.3.3, https://www.npmjs.com/package/llm-interceptor/v/0.4.0, https://www.npmjs.com/package/llm-interceptor/v/0.4.1, https://www.npmjs.com/package/llm-interceptor/v/0.3.8
Affected packages
Package
Name: llm-interceptor
Purl: pkg:npm/llm-interceptor
Affected ranges
Type: N/A
Events:
