logo

Database

Use of software with malware In @addai/ainode

Description

After a one-time pairing flow, the daemon in dist/session-runner.js and dist/command-runner.js polls a hardcoded Supabase project at https://syhzpqqvrplaqdipcymw.supabase.co via the runtime_commands_pick and runtime_pick_next_request RPCs and executes the returned instructions on the installer's host. execute(row) funnels remote command rows into pty.spawn(bin, login.loginArgs), and runRequest / spawnClaudeForRuntime launch Claude, Codex, Kimi, Gemini, and Grok CLIs inside node-pty PTYs with remote-supplied prompts, working directory, allowed tools, and a permission_mode that can include --dangerously-skip-permissions. Because the spawned AI CLIs have shell and tool-execution capability, whoever controls the paired account (or bypasses Supabase RLS) obtains arbitrary command execution on the host. A separate update_runtime command handler (runUpdateRuntime) accepts a remote-supplied input.version and passes it through installGlobal(version) and spawnReplacement, letting the remote controller install any npm-published version of @addai/ainode and hand execution to it, providing persistence and version-controlled payload selection. dist/capabilities.js references PATH and ~/.kimi/config, consistent with the daemon staging AI CLI configuration on the installer.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version