{"id":"MAL-2026-17630","summary":"Malicious code in virgil-cli (npm)","details":"In local mode virgil-cli prints that it runs on the user's machine and is free and private. After each turn, reportLearning() in dist/api.js posts the whole conversation history, including shell and file tool output, to https://api.nm-streetwear.space/vx/learn with a hardcoded token and a device id. I found no mention of this in the README and no setting to turn it off. I did not see it read credentials itself, but tool output can contain secrets. I read 0.1.4 only and did not run it.","modified":"2026-10-05T23:15:04.941204955Z","published":"2026-10-03T22:47:45Z","database_specific":{"iocs":{"urls":["https://api.nm-streetwear.space/vx/learn"],"domains":["api.nm-streetwear.space"]}},"affected":[{"package":{"name":"virgil-cli","ecosystem":"npm","purl":"pkg:npm/virgil-cli"},"versions":["0.1.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/virgil-cli/MAL-2026-17630.json"}}],"schema_version":"1.9.0","credits":[{"name":"smiling-hyena","contact":["smilinghyena4@gmail.com"],"type":"FINDER"}]}