MAL-2026-13455Malicious code in remote-claude-daemon (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | remote-claude-daemon | 0.3.0 |
| npm | remote-claude-daemon | 0.3.4 |
| npm | remote-claude-daemon | 0.3.5 |
| npm | remote-claude-daemon | 0.3.6 |
| npm | remote-claude-daemon | 0.3.7 |
| npm | remote-claude-daemon | 0.3.8 |
| npm | remote-claude-daemon | 0.3.9 |
| npm | remote-claude-daemon | 0.4.2 |
| npm | remote-claude-daemon | 0.4.6 |
| npm | remote-claude-daemon | 0.4.7 |
| npm | remote-claude-daemon | 0.5.0 |
| npm | remote-claude-daemon | 0.5.2 |
| npm | remote-claude-daemon | 0.5.4 |
| npm | remote-claude-daemon | 0.5.5 |
| npm | remote-claude-daemon | 0.5.7 |
| npm | remote-claude-daemon | 0.5.9 |
| npm | remote-claude-daemon | 0.6.0 |
| npm | remote-claude-daemon | 0.6.1 |
| npm | remote-claude-daemon | 0.6.2 |
| npm | remote-claude-daemon | 0.6.6 |
{"modified":"2026-08-06T23:29:20Z","published":"2026-08-06T19:57:03Z","schema_version":"1.7.4","id":"MAL-2026-13455","summary":"Malicious code in remote-claude-daemon (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c9c092b787277e3c89fc27a6c01e5360bc0566988cefca0b1a0f9626af9186d0)\nremote-claude-daemon connects to a hardcoded WebSocket relay at wss://remote-claude-relay.fly.dev and treats inbound messages as commands executed against the local host. On receiving ai_query/ai_voice_query messages, the daemon spawns the local `claude` binary with `--continue -p --dangerously-skip-permissions` and the remote-supplied prompt as input, giving the remote side arbitrary code execution through Claude Code's agent tooling with the permissions prompt disabled. A separate handleInput path dispatches remote messages to synthesised mouse moves/clicks, keyboard keypresses (including modifier chords) and clipboard paste via @nut-tree-fork/nut-js, giving the remote side full interactive control over the installer's desktop. The daemon additionally captures screen frames (native SCStream on macOS via a shipped Swift helper, ffmpeg gdigrab/x11grab on Windows/Linux) and optional microphone PCM audio and streams them over the same relay. Although the package is documented as a remote-Claude bridge, session tokens gate access, and `--relay` can override the default, the out-of-the-box configuration wires an author-controlled endpoint into an RCE + input-injection + screen/audio-capture surface on the installer. The relay operator (or anyone who obtains a session token, MITMs the connection, or compromises the relay) can execute arbitrary commands as the user, control input, and stream desktop/audio contents.\n","affected":[{"package":{"ecosystem":"npm","name":"remote-claude-daemon"},"versions":["0.3.9","0.3.7","0.3.5","0.5.7","0.4.6","0.5.2","0.5.5","0.6.0","0.3.0","0.4.2","0.3.8","0.3.6","0.5.4","0.6.1","0.6.6","0.6.2","0.5.9","0.4.7","0.5.0","0.3.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"cli.js","sha256":"64dc1b50be8626888195ca647f0c0224cb45ce9a23c17c00fa7670619f669f63","tlsh":"3b22968599f900320b4270f0b89b614a37f696233b4e8990776df3692f96c74cdb2b5d"}],"package_integrity":[{"filename":"remote-claude-daemon-0.3.9.tgz","hashes":{"sha1":"c252ea3644d3a04a4c94c649ec6a18c0fc697f73","sha512_sri":"sha512-rM+e+gleiFxfWKZ/ZWxphECmUDxBrmYHVMPlETFj5TF9W0prMgIIyWY8PaHYxBRPnIPNWuMk4+HxY8tcBYDxSA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.5.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.4.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.5.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.5.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.6.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.4.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.5.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.6.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.6.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.6.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.5.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.4.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/remote-claude-daemon/v/0.3.4"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016840","import_time":"2026-08-06T23:25:11.919982696Z","modified_time":"2026-08-06T19:59:32Z","sha256":"0cc04b385ce0585b65983f0a9800753ae9000d6506fbdd1f1ab0fd9591dc2643","source":"amazon-inspector","versions":["0.3.9"]},{"id":"IN-MAL-2026-016830","import_time":"2026-08-06T23:25:11.492150109Z","modified_time":"2026-08-06T19:58:07Z","sha256":"50134d71be77b2111f5b2cc42083ee520f5763483c5ef9dd0fe9aa14a52ff9d5","source":"amazon-inspector","versions":["0.3.7"]},{"id":"IN-MAL-2026-016838","import_time":"2026-08-06T23:25:11.844299368Z","modified_time":"2026-08-06T19:59:14Z","sha256":"a72c85f56c6186749a871921c442a4c2711cf2df0d670a33b807c0ce6343fbd8","source":"amazon-inspector","versions":["0.3.5"]},{"id":"IN-MAL-2026-016841","import_time":"2026-08-06T23:25:11.953840318Z","modified_time":"2026-08-06T19:59:40Z","sha256":"e43c80e65e48e1ec6433a1c852417322053c8a0821c6dc217cdfc3132b8e1d65","source":"amazon-inspector","versions":["0.5.7"]},{"id":"IN-MAL-2026-016824","import_time":"2026-08-06T23:25:11.248013875Z","modified_time":"2026-08-06T19:57:11Z","sha256":"e54c94a33cacd1f687a1f98ce1f643fc974757d24b1b3eeeb89cf733edcd5112","source":"amazon-inspector","versions":["0.4.6"]},{"id":"IN-MAL-2026-016842","import_time":"2026-08-06T23:25:12.004416819Z","modified_time":"2026-08-06T19:59:48Z","sha256":"6ffaf23dc23ad649fbff35601d721add3231336aeb914e3129017a48b40836ba","source":"amazon-inspector","versions":["0.5.2"]},{"id":"IN-MAL-2026-016827","import_time":"2026-08-06T23:25:11.397126423Z","modified_time":"2026-08-06T19:57:38Z","sha256":"7299ef4f42a0465f6d27d7932857f00b2c8fd133ba9bc0f5a97eb98768cf1eaf","source":"amazon-inspector","versions":["0.5.5"]},{"id":"IN-MAL-2026-016823","import_time":"2026-08-06T23:25:11.178394824Z","modified_time":"2026-08-06T19:57:03Z","sha256":"9ad1628dace09d9945234d24dfbf8460e044bd303bdac8d37b2ae3e77af3daa2","source":"amazon-inspector","versions":["0.6.0"]},{"id":"IN-MAL-2026-016831","import_time":"2026-08-06T23:25:11.559680948Z","modified_time":"2026-08-06T19:58:15Z","sha256":"a720602241452b95fbb1bd58f9a4e407cbd5c56a5945f90d92a2103ddb4755a2","source":"amazon-inspector","versions":["0.3.0"]},{"id":"IN-MAL-2026-016837","import_time":"2026-08-06T23:25:11.811648908Z","modified_time":"2026-08-06T19:59:06Z","sha256":"c9c092b787277e3c89fc27a6c01e5360bc0566988cefca0b1a0f9626af9186d0","source":"amazon-inspector","versions":["0.4.2"]},{"id":"IN-MAL-2026-016828","import_time":"2026-08-06T23:25:11.425839781Z","modified_time":"2026-08-06T19:57:49Z","sha256":"d39ae95f369db5d8e9e20835caf67b4faa5e6a3f9359598e5612923c39307c22","source":"amazon-inspector","versions":["0.3.8"]},{"id":"IN-MAL-2026-016829","import_time":"2026-08-06T23:25:11.4556546Z","modified_time":"2026-08-06T19:57:59Z","sha256":"e5e42c8fbbd44722f748855ec2a2d4827bb81dec178dc00bc82f6d9af3829bd2","source":"amazon-inspector","versions":["0.3.6"]},{"id":"IN-MAL-2026-016833","import_time":"2026-08-06T23:25:11.662874478Z","modified_time":"2026-08-06T19:58:33Z","sha256":"30ce1f921742260706c6eb2ea95030a8b8f68c72d8558cb886f40ce1e098a5f4","source":"amazon-inspector","versions":["0.5.4"]},{"id":"IN-MAL-2026-016834","import_time":"2026-08-06T23:25:11.709344919Z","modified_time":"2026-08-06T19:58:42Z","sha256":"5409ee612b4b78d004abcd66a068bd4528955058775d036e110cdf251147673a","source":"amazon-inspector","versions":["0.6.1"]},{"id":"IN-MAL-2026-016832","import_time":"2026-08-06T23:25:11.620168317Z","modified_time":"2026-08-06T19:58:24Z","sha256":"990358496227dbad6bfee52cd7347d719faefd55706c10d4997c5c37a4e7dc7d","source":"amazon-inspector","versions":["0.6.6"]},{"id":"IN-MAL-2026-016826","import_time":"2026-08-06T23:25:11.338561556Z","modified_time":"2026-08-06T19:57:30Z","sha256":"a7019993eb984de1e92741ebe82f5b7e4979ec53c1183346709c35d5570d5642","source":"amazon-inspector","versions":["0.6.2"]},{"id":"IN-MAL-2026-016836","import_time":"2026-08-06T23:25:11.77216931Z","modified_time":"2026-08-06T19:58:59Z","sha256":"c793a392c49c28554c2a9cc08f6b624c1b74053f931838fba523ede41ffdfce9","source":"amazon-inspector","versions":["0.5.9"]},{"id":"IN-MAL-2026-016825","import_time":"2026-08-06T23:25:11.291325019Z","modified_time":"2026-08-06T19:57:20Z","sha256":"e1097341da0486b1c28d3832da222a07870523da997f3706180f8554faf8fe37","source":"amazon-inspector","versions":["0.4.7"]},{"id":"IN-MAL-2026-016839","import_time":"2026-08-06T23:25:11.876134957Z","modified_time":"2026-08-06T19:59:22Z","sha256":"f1af8e496aec6ca98a7745973c975b57171e3d5172329b0c7e6485754824fb6a","source":"amazon-inspector","versions":["0.5.0"]},{"id":"IN-MAL-2026-016835","import_time":"2026-08-06T23:25:11.734958179Z","modified_time":"2026-08-06T19:58:49Z","sha256":"45b583bf566b2e76ef5fffb777a63d8b572ff6598b8ee312424f8fee2806d567","source":"amazon-inspector","versions":["0.3.4"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0