{"id":"MAL-2026-10720","summary":"Malicious code in @vibelet/cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3f3dc6503f9f63413994c6d0b2e19f22ebcf17f5e7ba9f713ce26ecf69c92c6c)\nThe @vibelet/cli package ships a daemon bundle (dist/index.cjs, invoked by the `vibelet` bin and by `vibelet start`/`restart`/`reset`) that starts an HTTP+WebSocket server, spawns an interactive PTY running process.env.SHELL via node-pty, and pipes network-received 'input' and 'resize' messages into that PTY. By default the CLI provisions a public Cloudflare tunnel (trycloudflare.com, using the bundled `cloudflared` and `ws` dependencies) that fronts this endpoint, so any remote party that pairs with the daemon (or obtains the tunnel URL together with the short-lived pair token) can execute arbitrary commands in a full interactive shell on the installer's host. The daemon bundle is packed with obfuscator.io-style transforms (string-array dispatcher `_0x9d44`, hex-encoded identifiers, control-flow flattening) rather than ordinary minification, which obscures the network-to-PTY path.\n","modified":"2026-07-16T19:19:38.149922360Z","published":"2026-07-16T18:39:32Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-16T18:39:32Z","sha256":"3f3dc6503f9f63413994c6d0b2e19f22ebcf17f5e7ba9f713ce26ecf69c92c6c","source":"amazon-inspector","versions":["1.2.154"],"id":"IN-MAL-2026-010734","import_time":"2026-07-16T18:54:01.803381806Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@vibelet/cli/v/1.2.154"}],"affected":[{"package":{"name":"@vibelet/cli","ecosystem":"npm","purl":"pkg:npm/%40vibelet/cli"},"versions":["1.2.154"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"9435f85063c07968634f8fb7b327b0e5e52e0c9e348c4c5fe064bd2529e6617e6e9a34","path":"dist/index.cjs","sha256":"bd72fe4bd5d15350f624e922b7fdc676e87e7bb680dbc1a573890fa0ef578a72"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-IN5qdJV0j9LAZc56nWUb5WFq51NPrYYBSJHEDPFVecq/1nD4XEU0Y1s0J9BJ3m3B7PYrJL9Ud81m7GtqzV/SQA==","sha1":"0bad1013d192d1319989663da8f901b85fbd8ba5"},"filename":"cli-1.2.154.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@vibelet/cli/MAL-2026-10720.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}