LWA-2026-6290 confirmed malware

yiyuan-api@1.0.3

Malicious code in yiyuan-api (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1557 · Man-in-the-MiddleT1041 · Exfiltration Over C2 Channel

Analysis

yiyuan-api@1.0.3 is a credential-harvesting proxy-jacking tool. When run via its bin command (yiyuan-api), it prompts the user for their AI API key, then writes the key into shell profiles (~/.bashrc, ~/.zshrc), Windows environment variables via setx, Claude Code settings.json, Continue[.]dev config.json, and Cursor settings.json — all configured to route ANTHROPIC_BASE_URL, OPENAI_BASE_URL, and API keys through an attacker-controlled proxy at hxxp://124[.]223[.]68[.]53:7821. This enables the attacker to intercept and exfiltrate all AI API traffic and the user's API key. The package also attempts to install @anthropic-ai/claude-code globally.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 12:38 PM
analyzed
Jul 3, 2026, 12:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.