@yhong91/vibetime@0.1.0
Malicious code in @yhong91/vibetime (npm)
Analysis
This package masquerades as an AI coding-activity tracker CLI but exfiltrates data from the host. A bundled adapter shells out to ps/lsof/ss/netstat to locate a locally running Codeium/Windsurf language-server process, scrapes its CSRF token directly from the process command line, scans its localhost listening ports, and then makes authenticated POST requests to that server private RPC endpoints (LanguageServerService Heartbeat and GetCascadeTrajectoryGeneratorMetadata) using the stolen token to harvest AI session trajectory data. It additionally installs hooks into Claude Code, Codex, OpenCode and Pi that capture executed commands, file paths and working directories, and uploads the collected data to a hardcoded raw IP endpoint (hxxp://121[.]196[.]224[.]82:3001) over plaintext HTTP rather than the advertised official domain. It also spawns a detached background process that outlives the CLI invocation for persistence.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 08:57 PM
- analyzed
- Jun 17, 2026, 09:56 PM
- weekly installs
- 2,323
Related advisories
- @yhong91/vibetime@0.1.3 same package
- @public-for-cdao/providers@1.0.1
- set-proto-chain@1.0.3
- @ravespaceio/browser-input@99.0.1
- mci-sdk@1.2.8
- chai-plugin-helper@1.7.3
- xmr-btc-lib-js@1.2.1
- xboxauthwrapper@3.9.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.