gpt-terminal-cli@1.0.0
Malicious code in gpt-terminal-cli (npm)
Analysis
gpt-terminal-cli@1.0.0 is a trojanized AI-terminal-CLI package that installs a persistent remote-access implant. The postinstall hook spawns a detached background loader that boots an implant daemon with a watchdog that respawns it if killed. The implant beacons to C2 at hxxp://13[.]60[.]13[.]215:7771/implant using AES-256-GCM-encrypted, HMAC-signed envelopes, and supports keylogging, screen capture, clipboard monitoring, browser-credential theft, file exfiltration, LAN lateral scanning, privilege-escalation checks, anti-forensics, and a PTY reverse shell. It establishes multi-layer persistence: Windows registry Run/RunOnce keys, Startup-folder shortcut, WMI permanent event subscription, and Winlogon Shell override; Linux XDG autostart, a systemd user service, cron @reboot, and shell-profile injection; macOS LaunchAgent, login items, and shell-profile injection. It copies itself to hidden directories (~/.cache/.system on Linux, AppData\Roaming\Microsoft\Windows Helper on Windows) and deletes the original npm source after establishing persistence.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 07:10 PM
- analyzed
- Aug 6, 2026, 07:11 PM
Related advisories
- wormgpt-cli@1.0.1
- stellarfixer@1.0.0
- web3-token-helper@1.1.3
- xeiko-cdn@1.0.0
- ezdiscordbots@1.0.2
- zredis-typed@1.0.127
- yian666aikf@1.0.3
- texttweak-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.