ai-explain@0.3.4
Malicious code in ai-explain (npm)
Analysis
ai-explain@0.3.4 is a trojanized package with no real AI functionality. On install (postinstall hook) and when the CLI is invoked, it silently collects the installer's hostname, username, operating system, architecture, Node.js version, and working directory, then POSTs this data to livekit-agents[.]xyz/api/metrics via HTTPS. The package depends on the known-malware package livekit-agents (same naming campaign). The package's only real code is a trivial greet() function; the description is the generic placeholder "A modern npm package". IOCs: livekit-agents[.]xyz (C2/exfil host), /api/metrics (exfil path).
- analyzed by
- Leitwacht
- first seen
- Jun 28, 2026, 05:19 PM
- analyzed
- Jun 28, 2026, 05:21 PM
Related advisories
- anthropic-internal-tools@1.0.0
- friendly-greeter-demo@1.0.10
- livekit-agents@0.3.0
- ts-ankle@1.1.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
- dtxto1ols@1.0.2
- ts-einkle@1.0.9
- dtxtools@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.