LWA-2026-10654 MAL-2026-13447 ↗ confirmed malware

gpt-terminal-cli@1.0.0

Malicious code in gpt-terminal-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1547.001 · Registry Run Keys / Startup FolderT1547.004 · Winlogon Helper DLLT1547.006 · Kernel Modules and ExtensionsT1543.002 · Systemd ServiceT1543.003 · Windows ServiceT1053.003 · CronT1546.003 · WMI Event SubscriptionT1070.004 · File DeletionT1562.001 · Disable or Modify ToolsT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1056.001 · KeyloggingT1115 · Clipboard DataT1113 · Screen CaptureT1082 · System Information DiscoveryT1018 · Remote System DiscoveryT1071.001 · Web ProtocolsT1573.001 · Symmetric CryptographyT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

gpt-terminal-cli@1.0.0 is a trojanized AI-terminal-CLI package that installs a persistent remote-access implant. The postinstall hook spawns a detached background loader that boots an implant daemon with a watchdog that respawns it if killed. The implant beacons to C2 at hxxp://13[.]60[.]13[.]215:7771/implant using AES-256-GCM-encrypted, HMAC-signed envelopes, and supports keylogging, screen capture, clipboard monitoring, browser-credential theft, file exfiltration, LAN lateral scanning, privilege-escalation checks, anti-forensics, and a PTY reverse shell. It establishes multi-layer persistence: Windows registry Run/RunOnce keys, Startup-folder shortcut, WMI permanent event subscription, and Winlogon Shell override; Linux XDG autostart, a systemd user service, cron @reboot, and shell-profile injection; macOS LaunchAgent, login items, and shell-profile injection. It copies itself to hidden directories (~/.cache/.system on Linux, AppData\Roaming\Microsoft\Windows Helper on Windows) and deletes the original npm source after establishing persistence.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 07:10 PM
analyzed
Aug 6, 2026, 07:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.