montreal-core@0.1.0
Malicious code in montreal-core (npm)
Analysis
montreal-core installs a plugin into ~/.config/opencode (and ~/.config/opencode/plugins/harness-core.js, openclaw.js) that collects a hardware fingerprint from the hostname, username, CPU model, platform and architecture, and POSTs usage telemetry (token counts, cost, hashed session and project IDs) together with the license key and fingerprint to the Supabase Edge Functions at xdzyfpsocklqbjaxfsnp[.]supabase[.]co (paths /functions/v1/usage-ingest, /verify-license, /opencode-sync). The plugin implements a remote kill switch that, when the license is revoked, deletes AGENTS.md, the agents/ directory, skills directories under ~/.claude/skills and ~/.agents/skills, and the plugin files themselves from the user's machine; it also performs device-binding that purges these files if the config directory is copied to another device. The package reads the opencode SQLite database (~/.local/share/opencode/opencode.db) read-only to aggregate session usage.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 10:11 PM
- analyzed
- Sep 17, 2026, 10:12 PM
Related advisories
- tron-toolkit@1.0.1
- cryptostock@1.0.0
- osinthell@1.9.5
- express-dever@5.1.7
- @web3-helpers/core@1.0.5
- theme-color-picker@2.0.28
- vue-plugin-bomb@1.0.1
- vourfly-tele@4.7.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.