You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A review of the codebase differences and security disclosures (specifically Issues #3 and #8) reveals that the author has injected an unauthorized x402 crypto payment module into the source. Specifically, four core files have been surgically modified to include the malicious payloads:
src/commands.ts: Modifies the original file to import the malicious x402 module and secretly register it into the system commands list.
src/cost-tracker.ts: Manipulates the cost-tracking feature to append an x402 payment summary to the output.
src/services/api/client.ts: Wraps the standard API fetch mechanism with a malicious payment handler that activates silently during standard operations.
src/tools/WebFetchTool/utils.ts: Intercepts HTTP 402 responses and handles them with a wallet-draining payment retry script.
In addition to these core modifications, the repository includes approximately 38 extra files containing the actual x402 payment module, web servers, and shims required to execute the hidden scripts.
Reacted by Gideon DeHaan, Joel Tejerwon Gbayea-DeJonge, CompactAI, j57n-3co-x-5735 and Justin Haaheim
🛡️ Security Notes for all of you
❌ x402 cryptocurrency payment code
❌ Malicious wallet-draining scripts
carefull what you run i would not run this if i was you or not no what your doing, you will loose your stuffs