Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@yancyyu/agentclinpm

@yancyyu/agentcli is a confirmed malicious npm package (MAL-2026-11123) that steals credentials and exfiltrates sensitive data (malicious versions 1.9.9, 1.9.10, 1.9.11…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @yancyyu/agentcli (npm)

MAL-2026-11123
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @yancyyu/agentcli

What this malware does

The npm package @yancyyu/agentcli ships a Feishu/Lark credential stealer. An auto-started telemetry worker (src/main/telemetry/worker.ts, started via agentcli init/agentcli usage start and macOS launchd) calls safeScanLarkCredentials() in its periodic run loop; the scan reads and decrypts local Lark credentials (macOS Keychain AES-256-GCM .enc under ~/Library/Application Support/lark-cli/, Windows DPAPI under HKCU\Software\LarkCli\keychain), refreshes tokens and POSTs {app_id, app_secret, access_token, refresh_token} to the operator backend (endpoint /api/v1/report/lark-credentials, later renamed /api/v1/feishu/lark-cli/credentials; default cloud hosts include agentbus.skg.com, 159.75.231.98:8088, 47.112.24.153).

These versions are not part of the existing OSV record MAL-2026-11123 (Amazon Inspector), which covers 1.9.25-1.9.80. The true malicious boundary is 1.9.9 (2026-07-12) via the import->call reachability chain (telemetry/worker.ts -> larkCredentials), 16 versions earlier than the previously-catalogued 1.9.25; the reachable credential theft is present continuously across 1.9.9-1.9.24 (each verified) and 1.10.0. Versions 1.8.8-1.9.8 exfiltrate local Claude/Codex conversations to the same backend but do not yet steal Lark credentials (out of scope for this malware record).

This report extends the confirmed-malicious set with 17 additional versions and an earlier boundary, scoped to the versions not yet listed in MAL-2026-11123 to avoid duplication. Determined by static code and dataflow review of the published npm tarballs.

The @yancyyu/agentcli package installs a telemetry worker (dist/telemetry-worker.bundle.mjs) that is started by agentcli init / agentcli usage start and auto-started via macOS launchd. The worker enumerates every lark-cli (Feishu) profile stored on the host — decrypting macOS Keychain-wrapped AES-256-GCM .enc files under ~/Library/Application Support/lark-cli/ and Windows DPAPI-protected values under HKCU\Software\LarkCli\keychain — refreshes each token, and batch-POSTs {app_id, app_secret, access_token, refresh_token} for every profile every 5 minutes to a hardcoded default endpoint http://47.112.24.153 (plain HTTP, bare IPv4, no TLS). The endpoint constant DEFAULT_OPENHERMIT_CLOUD_BASE_URL is the single default for the credential batch upload and conversation/usage pipelines when no override env var or settings value is present. The enumeration is not limited to AgentCli-created profiles; every lark-cli profile on the machine is harvested. The reportAllLarkCredentials code comment states: "enumerate all personal lark-cli profiles, refresh each, then read current credentials [...] batch the complete eligible set to the server." The postinstall step additionally rewrites the optional cc-connect dependency's installer to prepend third-party China GitHub mirror hosts (gh-proxy.com, ghproxy.net) in front of upstream release URLs before the cc-connect native binary is downloaded and executed, broadening the trust boundary for that binary. Feishu (Lark) app_id + app_secret combined with valid access/refresh tokens allow full impersonation of the affected tenant applications; sending them cleartext to a bare IPv4 over HTTP additionally exposes them to any on-path observer.

Malicious versions

44 flagged
1.9.91.9.101.9.111.9.121.9.131.9.141.9.151.9.161.9.171.9.181.9.191.9.201.9.211.9.221.9.231.9.241.9.251.9.261.9.271.9.281.9.291.9.301.9.321.9.331.9.351.9.361.9.401.9.421.9.431.9.441.9.481.9.501.9.521.9.531.9.581.9.611.9.661.9.671.9.711.9.771.9.781.9.791.9.801.10.0

Indicators of compromise (SHA-256)

10b67ca39014513878a16bd2459cd4f1e6ebf24934aa5784df51b9acc766f264
7a6db15f3c61b8f2b394478af94c4b9f58cdce9f5007012b8e0e5b883f8ccb81
88391b25e025074f89b9807478519246f9b12a7ad1929a0a04c4ba12eddf9a07
f9b6bcbf02d925d1138d0cedb9d31e8c78792d419bb0f1f165ac721b2a358803
56ca7986e94bf6014ed0c7aa7402d3c6db6e8f6de75d630f261465203cfc3cb7
56d4294e5480488e46551a40136052a1dd16c42720ea2509835db2d5fafc03a8
7babf0cc388e02d1f0b2939f1f68ce7b9714bc28c261932386300a3574d68397
9ac7f0e3c2c3e7754640b213b01d06f9ed75d672d64c1011ed6172a5792c21a0
9ee1f17b07ed88c1615d1570d311b968675bc579fc43e58fa72bf162f62dadb5
aa00d94088265daa445b5484137f5a8e3a642de907475f76618083fc21c562a8
b6f47205ab88810800770bb78e0bc408bc9ec3a7a4f25bf941f069241e1052cd
195ac70f37e1d413634857ce9b2028b4a6113f355b9b95893ac83db43918e590
4901552125568a59097d415d86ce33d8c58e34c310ff88e2c39e622a65a6004a
cd05293e460d530740baac9ed76214c8aebae2c1ec3e62a773f6d18201f23457
ce8aac20108e18ccadc4f507a2c46d8c68e02e1d4120ed71b7ea34be497de71a
e7dddfc8ef5507e863d3f9c5bfb41aa9f33c39576748180ed1f214a0e3b958fd
00eaee1d97d1213adb78e4d98f8a0e12b63a14aa047c2067790d0785d7f2dc29
96b9b67b6242662bc6764cc0477e0e068d57ca310d816c5f91fd76e2f61ec91b
bfddf2f96157ec5e79aef8c1a3f8bee90cb95a160ec4ae5cec019f0a63429cab
1a53d10f01aa0ae30707b0c4f940082ff6aa4ae8eb7d7261f8ce2be9a6236171
4b01add999e692277fe94d2e278051d1532c12ff73b569aea7013bd755ec1d7f
7f6774653f487db8fbb9b40f1c1aba2bf959edffae409445162b0d245a3bedf1
87e50624a116710c2841131b9d46d28093c452498a2b58b4330e62a316e33fb4
bfdc68ab10663e643ad339057a1e386c46e422f8eaa550cea595d068050dfbeb
d39f9ac9ca12736eaae21f8ec2a8a5b845ecdea82ef356b80521d1df95677d9a
efc4879d1133923b0f8cf97b5ee308ebc086f8379dff6196a0a2211bb958e248
fba4521811f608f2adaa7cb5d4b68681ccd1cfc196c0da20db38127b98a2dc25
f8374c4b2e280cc37e57bee526d18562310edf3e4ec4b999d8554666279eebd8

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @yancyyu/agentcli (44 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @yancyyu/agentcli across your stack and pipelines.

  2. If you installed it — respond

    @yancyyu/agentcli is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @yancyyu/agentcli was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @yancyyu/agentcli before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @yancyyu/agentcli on npm has been identified as a malicious package (versions 1.9.9, 1.9.10, 1.9.11, 1.9.12, 1.9.13, 1.9.14, 1.9.15, 1.9.16, and 36 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-010879IN-MAL-2026-014789IN-MAL-2026-014814IN-MAL-2026-014800IN-MAL-2026-017173IN-MAL-2026-017175IN-MAL-2026-017192IN-MAL-2026-017182IN-MAL-2026-017184IN-MAL-2026-017170IN-MAL-2026-017181IN-MAL-2026-017188IN-MAL-2026-017174IN-MAL-2026-017171IN-MAL-2026-017180IN-MAL-2026-017179IN-MAL-2026-017176IN-MAL-2026-017178IN-MAL-2026-017172IN-MAL-2026-017185IN-MAL-2026-017186IN-MAL-2026-017191IN-MAL-2026-017177IN-MAL-2026-017189IN-MAL-2026-017183IN-MAL-2026-017187IN-MAL-2026-017190IN-MAL-2026-019709

References

Credits

  • Amazon Inspector · finder
  • codelake Research · finder

Detect & block this

O3 blocks @yancyyu/agentcli-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@yancyyu/agentcli (npm) malicious package — MAL-2026-11123 | O3 Security