yiyuan-api@1.0.3
Malicious code in yiyuan-api (npm)
Analysis
yiyuan-api@1.0.3 is a credential-harvesting proxy-jacking tool. When run via its bin command (yiyuan-api), it prompts the user for their AI API key, then writes the key into shell profiles (~/.bashrc, ~/.zshrc), Windows environment variables via setx, Claude Code settings.json, Continue[.]dev config.json, and Cursor settings.json — all configured to route ANTHROPIC_BASE_URL, OPENAI_BASE_URL, and API keys through an attacker-controlled proxy at hxxp://124[.]223[.]68[.]53:7821. This enables the attacker to intercept and exfiltrate all AI API traffic and the user's API key. The package also attempts to install @anthropic-ai/claude-code globally.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 12:38 PM
- analyzed
- Jul 3, 2026, 12:49 PM
Related advisories
- polygon-gamma-apis@1.5.2
- ue-jenkins-buildkite@99999.0.0
- epic-internal-tools@99999.0.0
- robomerge@99999.0.0
- compose-logger-stand@1.0.126
- cursed-ecto-d3ab00@1.0.0
- mjs-eslint@7.0.7
- @marketfront/actualordersnippetpopup@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.