A commercial AI sales-call CLI that sends its users' login credentials in plaintext HTTP to a hardcoded IP
aicall-cli-x is a Chinese AI outbound-call (telemarketing) CLI for insurance / loan sales agents, talking to a Ping An backend (cfs-ms.pa18.com). Its published bundle is fully obfuscated, and alongside the official HTTPS host it hardcodes a “middleware” layer at http://39.96.50.154:8088 that receives the agent's username + password over plaintext HTTP. On update it also runs npm install -g of its own sibling packages. This is not malware — there is no theft of unrelated secrets and no backdoor — but the security hygiene endangers the tool's own users.
[email protected] (npm, bin aicall) is a commercial AI outbound-call / telemarketing CLI aimed at Chinese insurance and loan sales agents. Its Chinese UI strings are genuine sales-CRM content (customer follow-ups, interest-rate notes, WeChat hand-off) and it integrates a companion CLI localcrm. The package is a legitimate-purpose tool — this advisory is about how it is built and how it moves credentials, not about any malicious payload.
The published tarball ships three files: a thin bin/aicall.js shim and a single 372 KB fully obfuscated dist/bundle.cjs (javascript-obfuscator: hex-escaped string table, split-string concatenation, control-flow flattening, plus an anti-debug NODE_OPTIONS check). The build script is node scripts/obfuscate.mjs, and the obfuscator source is not published.
Deobfuscating the bundle statically (no execution) reveals two backends: the official https://cfs-ms.pa18.com (Ping An, read from ~/.aicallrc/config.json) and a hardcoded “middleware” layer at http://39.96.50.154:8088 (an Alibaba-Cloud Beijing IP, plain HTTP). The middleware functions send first-party API calls to that IP: middlewareLogin() POSTs {um_id, password} to /api/sales/login, and middlewareRecordDownload() fetches call recordings from /query/record-download with a bearer token.
The credentials transmitted are the tool's own sales-system login, sent to the tool's own backend — not the user's unrelated secrets. There is no harvesting of .ssh, .aws, .npmrc, browser data, .env files or /etc/passwd, and no exfiltration to a third-party drop. The execSync('npm install -g …@latest') seen on update installs a static, hardcoded list of the author's own sibling packages (skill-ai-outbound-calling(-x), skill-localcrm-operator(-x), aicall-cli-x) — a self-update, not a remote-controlled dropper.
The two dangerous properties — credentials over plaintext HTTP to a raw IP (interceptable on any shared network) and heavy obfuscation of a tool that handles those credentials — are what earn the Risky classification. Both are unchanged from the prior 0.0.20 release; the scanner note that 0.0.21 “adds the IP + obfuscation” is inaccurate — it is the same design.
Analyzed independently by codelake Research · AI-assisted triage + deterministic static deobfuscation of the packed bundle (no execution). Classified Risky tool: a legitimate-purpose tool whose security hygiene endangers its own users — not malware. codelake stores only the detection rule, indicators and analysis, never raw payloads.