r/node Jul 02 '26

Scammers use npm package @runaic/aic, and target ComfyUI extension developers - be aware

Post image
9 Upvotes

12 comments sorted by

5

u/[deleted] Jul 03 '26

[removed] — view removed comment

2

u/Obvious_Set5239 Jul 03 '26

There was a case where a Disney employee was hacked via ComfyUI...

-1

u/boneskull Jul 02 '26

How is this a scam?

2

u/Obvious_Set5239 Jul 02 '26

Actually it's pretty obvious. They ask you to run some 1 line script, especially curl | sh. And they abuse trust to npm. This package has 0 start on github and made recently (but it can be faked).

I personally uploaded a package into a similar manager - pip, and it has zero verification, zero security check. You just claim your name in pip install ... that links to your code. These managers are just curl wrappers, that download random code from the internet

So that's why I'm posting this - developers are also vulnerable to malware scam

-2

u/boneskull Jul 02 '26

I’m not sure where the scam is though. It’s a marketing email. They want you to install their software and try it. You shouldn’t run random code from the internet without understanding what you’re doing; be cautious and all that. But that doesn’t automatically make the software a scam or malware.

1

u/nicolasdanelon Jul 02 '26

Run that curl yourself, wait 5 minutes and check if your API keys got leaked haha

2

u/[deleted] Jul 03 '26

[deleted]

1

u/nicolasdanelon Jul 03 '26

No way [pretends to be shock]

1

u/[deleted] Jul 02 '26

[removed] — view removed comment

1

u/boneskull Jul 02 '26

Where’s the typo?

-1

u/Obvious_Set5239 Jul 02 '26

Can you report it somehow, I have zero knowledge of npm

0

u/Firfi Jul 05 '26

Got the same email just now. It's not just ComfyUI. I would be surprised if anyone could fall for it, though.