{"id":"MAL-2026-6375","summary":"Malicious code in gpt-chat-cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e8890af695b137878736a36dae473487015eb1954c494fec0b5a6041f0817832)\ncollect.js bundles a host-reconnaissance and exfiltration payload. It loads child_process, fs, os, http, and https, reads os.hostname() and os.homedir(), enumerates filesystem paths via fs.existsSync(), and POSTs the collected data to the hardcoded endpoint http://aab.sportsontheweb.net (collect.js line 13, POST at line 366). The destination is unrelated to any documented purpose of a 'GPT chat CLI' package and matches the shape of a system-information stealer. Installing this package places attacker-controlled data-collection code into the install tree.\n","modified":"2026-06-24T06:31:21.715302242Z","published":"2026-06-24T06:02:01Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-007424","import_time":"2026-06-24T06:23:52.065262355Z","modified_time":"2026-06-24T06:02:01Z","sha256":"8ccdee952af3407e4e33c563dcd8cab4fe48d6a9ddeea6e008b4dbda0f7ce578"},{"sha256":"e8890af695b137878736a36dae473487015eb1954c494fec0b5a6041f0817832","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-007425","import_time":"2026-06-24T06:23:52.095582607Z","modified_time":"2026-06-24T06:02:04Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/gpt-chat-cli/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/gpt-chat-cli/v/1.0.2"}],"affected":[{"package":{"name":"gpt-chat-cli","ecosystem":"npm","purl":"pkg:npm/gpt-chat-cli"},"versions":["1.0.1","1.0.2"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"44a21e5b14cb351ac747e70ad7670014ad88abb3b113bb41bb8c9bd41f2ad2662d09f9","path":"collect.js","sha256":"463735e1a5b9150efad9ef66856033363d7ffb55490e84d1bf450c0e1406ef4d"}],"package_integrity":[{"filename":"gpt-chat-cli-1.0.1.tgz","hashes":{"sha1":"56255bcf307bd0c2c6ff8dc71db64bc0432fe7f6","sha512_sri":"sha512-Nx2DouxnShkwdL5Aty0TMnrKpBrdRIc3BTnm26iIDmHT3UTOirdruxV1Xk2z/jdVOCTwDrmHUMxxSMIsdVrhAg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gpt-chat-cli/MAL-2026-6375.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}