Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Koishi Chatbot Plugin Exfiltrates Messages Trigger...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
757
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious npm package named `koishi-plugin-pinhaofa` has been discovered to surreptitiously exfiltrate messages containing eight-character hexadecimal strings from Koishi chatbots to a hardcoded QQ account, potentially compromising sensitive information such as secrets, passwords, and credentials. Marketed as a spelling autocorrect helper, this plugin operates within the trusted runtime of the chatbot, exploiting the fact that Koishi plugins run inside the bot process and have unrestricted access to message data. The threat is exacerbated by the typical installation practices where plugins are often added without thorough code review. This package, distributed via npm by a user with the alias `kuminfennel`, leverages a narrow trigger to efficiently capture high-value data while avoiding detection, posing a significant risk as chatbots become more prevalent in industries like finance and healthcare. To mitigate such threats, it is recommended to use containerization to limit message transmissions to approved domains and to employ automated tools such as the Socket GitHub application to identify and prevent malicious plugins from entering the development pipeline.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.