mal-2026-16013

osv_npm
Description

The npm package `agent-free` is malicious. It is one of five AI-coding-CLI impersonations published to npm by `imjustbetterxd` (a coordinated campaign). On use, the CLI reads the developer's LLM/provider API key - from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY) and its own config - and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's `Authorization: Bearer <apiKey>` together with the chat prompt and code context, so the backend operator receives the API key and everything the developer sends to their assistant. Later builds set `rejectUnauthorized: false` / `NODE_TLS_REJECT_UNAUTHORIZED` for the relay connection. Payloads/updates are hosted on the GitHub account `Marcus-Mok-GH`. The single published version (1.0.0) is affected. It relays to `fireworks-endpoint--57crestcrepe.replit.app` - the same backend used by codebuff-cli (1.0.4/1.0.10) and orbitron-tui (1.0.x), confirming the shared operator.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/agent-free/MAL-2026-16013.json"
      },
      "package": {
        "ecosystem": "npm",
        "name": "agent-free",
        "purl": "pkg:npm/agent-free"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "SEMVER"
        }
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "https://research.codelake.dev"
      ],
      "name": "codelake Research",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "iocs": {
      "domains": [
        "fireworks-endpoint--57crestcrepe.replit.app"
      ]
    }
  },
  "details": "The npm package `agent-free` is malicious. It is one of five AI-coding-CLI impersonations published to npm by `imjustbetterxd` (a coordinated campaign). On use, the CLI reads the developer's LLM/provider API key - from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY) and its own config - and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's `Authorization: Bearer <apiKey>` together with the chat prompt and code context, so the backend operator receives the API key and everything the developer sends to their assistant. Later builds set `rejectUnauthorized: false` / `NODE_TLS_REJECT_UNAUTHORIZED` for the relay connection. Payloads/updates are hosted on the GitHub account `Marcus-Mok-GH`.\n\nThe single published version (1.0.0) is affected. It relays to `fireworks-endpoint--57crestcrepe.replit.app` - the same backend used by codebuff-cli (1.0.4/1.0.10) and orbitron-tui (1.0.x), confirming the shared operator.",
  "id": "MAL-2026-16013",
  "modified": "2026-09-11T04:00:07.771762877Z",
  "published": "2026-09-04T00:00:00Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3051-agent-free"
    },
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3048-ai-cli-relay-campaign"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "Malicious code in agent-free (npm)"
}
View JSON API Download JSON