
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
aihawk
Advanced tools
AIHawk is an anti detect browser and web browsing agent, open source, with an MCP server for coding agents: undetected, no captchas, no blocks. Tell it what you want in plain language.
FEATURED IN
Business Insider ·
TechCrunch ·
Semafor ·
Wired ·
The Verge ·
Vanity Fair ·
404 Media
Windows, in PowerShell:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
$env:Path = "$env:USERPROFILE\.local\bin;$env:Path"
uvx invisible-playwright fetch
Linux:
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
uvx invisible-playwright fetch
Then tell your assistant it exists.
Claude Code:
claude mcp add --scope user stealth -- uvx aihawk
Codex:
codex mcp add stealth -- uvx aihawk
Gemini CLI:
gemini mcp add --scope user stealth uvx aihawk
We bring the interface, you bring an OpenRouter key. Chat on the left, the live browser on the right.
Windows, in PowerShell:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
$env:Path = "$env:USERPROFILE\.local\bin;$env:Path"
uvx invisible-playwright fetch
uvx aihawk ui --openrouter-key sk-or-...
Linux:
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
uvx invisible-playwright fetch
uvx aihawk ui --openrouter-key sk-or-...
Then open http://127.0.0.1:8765 and type the same thing.
Anything that needs real web automation: a browser rather than an API, and a person's judgement about what is on the page.
Go to
<paste the URL>. One way, Milan to Lisbon, economy, one checked bag, one adult. Check every date from the 12th to the 16th of next month, one at a time, and read the cheapest fare for each day. The date field is a calendar widget, so click the days rather than typing them. If a date has no availability, say so. Do not guess a number.
It drives the page the way a person would: the pointer moves, keys are pressed.
--openrouter-key Your key, or the OPENROUTER_API_KEY variable.--model An OpenRouter model id, or AIHAWK_MODEL. Defaults to z-ai/glm-5.3-flash.--proxy Optional. http://user:pass@proxy.example.com:8080 or
socks5://proxy.example.com:1080. Host and port are both required. The
timezone, locale and egress follow it.--binary An engine binary you already have. It must be the build the seal
pins, or startup refuses: this skips the download, not the version check.--seed An integer. Same seed, same browser identity, every run.--profile-dir A directory to keep the profile in, so logins and cookies
survive restarts.--headed Show the browser window. The interface shows you the page anyway.--host, --port 127.0.0.1 and 8765. Changing the host
exposes an interface that has no authentication..env beside the commandRather than retyping the key and the binary path, put them in a .env in the
directory you run from:
OPENROUTER_API_KEY=sk-or-...
STEALTHFOX_BINARY=/path/to/firefox
It is read at startup, and on the way in it never overrides something
already set, so the order is --flag > the environment > .env > the default.
Only the directory you are in is read - there is no search upwards, so running
from a subfolder cannot silently pick up a different key. The startup line names
the variables it applied and never prints their values.
Passing --openrouter-key puts the key in your shell history, and on Linux in
the process list. OPENROUTER_API_KEY in the environment or in a .env avoids
both.
The reading room around the agent lives in the wiki: the AI browser-agent landscape: browser-use, Operator-style and computer-use agents compared, what to check when an agent gets blocked, and what happened to OpenAI Operator, among others. Worked examples, transcripts and their outputs live in articles/.
The MCP server from option 1 ships inside this package: aihawk with no
subcommand is the server, aihawk ui the interface. Its config blocks for
clients that take a file, its settings and its tools are on the wiki page
The MCP server.
This automates a browser under your control. Read the terms of the sites you point it at, respect their rate limits, and do not submit anything a human has not read.
AIHawk runs on your machine and has no server of its own. What leaves your computer, and to whom:
uvx invisible-playwright fetch, and a GeoIP database is when a proxy is
set. Each browser launch also fetches a one-line counter file from a GitHub
release, which is how launches are counted: the request carries no
identifier and nothing of yours, and GitHub sees what any HTTPS request
shows, your IP address.Nothing else is collected and nothing is sent to the author. Sessions,
profiles and screenshots are stored locally, under AIHAWK_HOME if set and
otherwise in the application-data directory of your system, and are yours to
delete; nothing is retained anywhere else. Questions go to the
issues.
MIT. Everything distributed before 2 September 2026 was released under AGPL-3.0 and stays under it.
FAQs
Anti detect browser and web browsing agent: undetected, no captchas, no blocks
We found that aihawk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.