⚠ Risky-Tool Advisory Analyzed codelake triage · 2026-09-29
A security-hygiene observation, not a malware finding. This advisory documents dangerous security practices in a legitimate-purpose tool — for example transmitting credentials over plaintext HTTP, heavy code obfuscation, or automatic global installs. It is not a claim of theft, backdoor or malicious intent: the tool does what it advertises, and the risk falls on its own users and their data. It is published so operators can make an informed decision before installing or deploying it.
Advisory · CLR-2026-3061

A commercial AI sales-call CLI that sends its users' login credentials in plaintext HTTP to a hardcoded IP

aicall-cli-x is a Chinese AI outbound-call (telemarketing) CLI for insurance / loan sales agents, talking to a Ping An backend (cfs-ms.pa18.com). Its published bundle is fully obfuscated, and alongside the official HTTPS host it hardcodes a “middleware” layer at http://39.96.50.154:8088 that receives the agent's username + password over plaintext HTTP. On update it also runs npm install -g of its own sibling packages. This is not malware — there is no theft of unrelated secrets and no backdoor — but the security hygiene endangers the tool's own users.

HighRisky toolPlaintext-HTTP credentialsObfuscated bundleAuto global npm installNo secret exfil / not malwarePresent since ≤ 0.0.20
Summary

[email protected] (npm, bin aicall) is a commercial AI outbound-call / telemarketing CLI aimed at Chinese insurance and loan sales agents. Its Chinese UI strings are genuine sales-CRM content (customer follow-ups, interest-rate notes, WeChat hand-off) and it integrates a companion CLI localcrm. The package is a legitimate-purpose tool — this advisory is about how it is built and how it moves credentials, not about any malicious payload.

The published tarball ships three files: a thin bin/aicall.js shim and a single 372 KB fully obfuscated dist/bundle.cjs (javascript-obfuscator: hex-escaped string table, split-string concatenation, control-flow flattening, plus an anti-debug NODE_OPTIONS check). The build script is node scripts/obfuscate.mjs, and the obfuscator source is not published.

Why this is Risky, not Malware

Deobfuscating the bundle statically (no execution) reveals two backends: the official https://cfs-ms.pa18.com (Ping An, read from ~/.aicallrc/config.json) and a hardcoded “middleware” layer at http://39.96.50.154:8088 (an Alibaba-Cloud Beijing IP, plain HTTP). The middleware functions send first-party API calls to that IP: middlewareLogin() POSTs {um_id, password} to /api/sales/login, and middlewareRecordDownload() fetches call recordings from /query/record-download with a bearer token.

The credentials transmitted are the tool's own sales-system login, sent to the tool's own backend — not the user's unrelated secrets. There is no harvesting of .ssh, .aws, .npmrc, browser data, .env files or /etc/passwd, and no exfiltration to a third-party drop. The execSync('npm install -g …@latest') seen on update installs a static, hardcoded list of the author's own sibling packages (skill-ai-outbound-calling(-x), skill-localcrm-operator(-x), aicall-cli-x) — a self-update, not a remote-controlled dropper.

The two dangerous properties — credentials over plaintext HTTP to a raw IP (interceptable on any shared network) and heavy obfuscation of a tool that handles those credentials — are what earn the Risky classification. Both are unchanged from the prior 0.0.20 release; the scanner note that 0.0.21 “adds the IP + obfuscation” is inaccurate — it is the same design.

Indicators & characteristics
PKGaicall-cli-x — npm, v0.0.21 (bin: aicall); ships bin/aicall.js + obfuscated dist/bundle.cjs only
HOSThttp://39.96.50.154:8088 — hardcoded middleware (raw IP, plaintext HTTP, Alibaba Cloud Beijing)
HOSThttps://cfs-ms.pa18.com — official backend (Ping An), read from ~/.aicallrc/config.json
APIPOST /api/sales/login body {um_id, password} — credentials sent over plaintext HTTP
APIGET /query/record-download — call-recording download, Authorization: Bearer
EXECexecSync('npm install -g @latest') on self-update
OBFdist/bundle.cjs — javascript-obfuscator (hex string table, split-string concat, control-flow flattening, anti-debug NODE_OPTIONS check)
Response & guidance
#ActionPriority
01 Do not enter credentials over an untrusted network. The sales login (um_id + password) is POSTed in plaintext HTTP to http://39.96.50.154:8088 and can be read or altered by anyone on the same network path. Treat any password used with this tool as exposed and rotate it if it is shared with other systems. Warning
02 Expect automatic global installs. Updating the tool runs npm install -g of the author's sibling packages; run it only on a machine where unattended global npm installs are acceptable. Caution
03 Vendor fix: serve the middleware over HTTPS with a real certificate (not a raw IP), stop shipping credentials over plaintext HTTP, and drop the silent npm install -g in favour of an explicit, user-initiated update. Fix

Analyzed independently by codelake Research · AI-assisted triage + deterministic static deobfuscation of the packed bundle (no execution). Classified Risky tool: a legitimate-purpose tool whose security hygiene endangers its own users — not malware. codelake stores only the detection rule, indicators and analysis, never raw payloads.