Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ MAL-2026-13466 — wormgpt-cli

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in wormgpt-cli (npm)

Source: amazon-inspector

The package's bin entries (wormgpt-cli, wormgpt, deepholegpt, wgpt) map to bin/victim.js, which silently spawns a detached implant on any invocation (including --help/--version). The implant connects to a hardcoded C2 at http://13.60.13.215:7771 over an AES-256-GCM/HMAC-signed protocol with pool failover and a DNS TXT dead-drop channel (protocol.js pollDnsDeaddrop) that rotates the C2 URL and shared secret at runtime. On beacon, implant.js gatherInfo() collects hostname, user, OS, architecture, PID, cwd, home, LAN IP, admin flag, and a persistent victim_id, and accepts opcodes for shell/PowerShell execution, interactive PTY reverse shell, file up/download, keylogging (GetAsyncKeyState PowerShell loop), clipboard capture, screenshots, LAN lateral-movement scanning, privilege-escalation checks, and anti-forensics wipe. stealers/browser.js reads Chrome/Edge/Brave/Opera/Vivaldi Login Data SQLite databases, decrypts DPAPI-protected passwords via PowerShell with an AMSI bypass stub (AMSI_BYPASS_B64 base64 blob run through powershell -EncodedCommand), parses Firefox logins.json, and regex-scans Discord/Chrome LevelDB for auth tokens (/[\w-]{24}\.[\w-]{6}\.[\w-]{27}|mfa\.[\w-]{84}/g), exfiltrating results via C2 opcode OP_BROWSER_DATA. persist.js installs persistence across six autostart layers per OS: Windows HKCU/HKLM Run keys, Startup.lnk, WMI __EventFilter/CommandLineEventConsumer permanent subscription, scheduled tasks, and hidden Windows Helper directories via attrib +H +S; Linux XDG autostart, systemd --user units, @reboot crontab, shell RC injection (.bashrc/.zshrc/.profile/.xinitrc), and /etc/rc.local; macOS LaunchAgent plist with KeepAlive and Login Items via osascript. loader.js runs a watchdog sibling process (poll every 20s, MAX_REVIVES = 50) plus uncaughtException respawn to keep the implant alive.

Affected software

MAL-2026-13466 is recorded against 1 package.

  • wormgpt-cli

Timeline and source

Published on 6 August 2026 and last revised on 7 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-08-06
Updated 2026-08-20
Modified 2026-08-07
Fix URL N/A

Affected Packages

Software From version Fixed in
wormgpt-cli

Free Vulnerability Check

Is your site affected by MAL-2026-13466?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-13466 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesMalicious packagesMalicious packages 2026