Logo
npm

agent-bot-api@1.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-12138

Ecosystem

npm

Summary

Package establishes a persistent remote-access channel to the hardcoded server https://server.junofficial.biz.id. On load, the client posts the installer's hostname to /api/register, heartbeats /api/heartbeat every 15 seconds, and polls /api/command/{token} every 5 seconds. Commands returned by the server are passed to child_process.exec with a configurable working directory, and additional operations perform arbitrary fs.readFile / fs.writeFile / rename / remove on the host filesystem. Command output is POSTed back to the same server. A server-issued token is persisted to.cache/publickey.txt, giving the operator persistent keyed reachability to the installer host. This is a full remote shell / RAT with attacker-controlled RCE on any machine that installs or runs the package.

Source: amazon-inspector (299eb5fe496022e888ed0663d0be82ddb8fac108bcb9a223291449982c360530)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.