codebuff-clinpm
codebuff-cli is a confirmed malicious npm package (MAL-2026-4533) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.11, 1.0.12, 1.0.14…). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in codebuff-cli (npm)
What this malware does
The package name codebuff-cli impersonates the legitimate codebuff npm package; the README is copy-pasted from the official CodebuffAI project (it even instructs users to run npm install -g codebuff), but the published artifact is an unofficial fork. Three concrete installer-side harms are present:
- Silent relay of user data to a non-publisher backend. README and the bundled binary configure the default backend as
https://fireworks-api-backend.vercel.app(a personal Vercel deployment) instead of codebuff.com. Because this CLI is an AI coding agent, by-default usage transmits the user's source code, prompts, and command history to that endpoint. - TLS verification globally disabled.
cli/bin/codebuff.cjsline 201 spawns the codebuff binary withNODE_TLS_REJECT_UNAUTHORIZED=0, disabling certificate verification for every HTTPS connection the binary makes (auth, backend, model providers). Combined with the redirected backend, this allows MITM of all transmitted code/prompts/credentials with no warning. - Unverified binary fetch from a mutable personal-account release. If the bundled binary is missing,
cli/bin/codebuff.cjsquerieshttps://api.github.com/repos/Marcus-Mok-GH/codebuff-cli/releases/latest, downloadscodebuff-<platform>-<arch>to~/.codebuff/bin/, chmods 0755, and executes it — with TLS verification disabled and no hash/signature check. Thelatesttag is mutable and the publisher is a personal GitHub user, not the CodebuffAI org.
Attacker benefit is concrete and sustained: every prompt, code excerpt, and credential entered by an installer who followed the README's codebuff instructions is delivered to the publisher's infrastructure over an unverified TLS channel, with the additional ability to swap the executable at any time through the mutable latest release pointer.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Credential / info stealerFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for codebuff-cli (26 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging codebuff-cli across your stack and pipelines.
If you installed it — respond
codebuff-cli is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.
Did it already run?
If codebuff-cli was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks codebuff-cli before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks codebuff-cli-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.