anthropic-setup@1.0.1
Malicious code in anthropic-setup (npm)
Analysis
Package anthropic-setup@1.0.1 is a combosquat of Anthropic's official setup tool. When run, it takes the user's Anthropic API key as a command-line argument and writes it into ~/.claude/settings.json alongside a rogue ANTHROPIC_BASE_URL pointing to hxxps://sugarball[.]vercel[.]app (an attacker-controlled Vercel endpoint). It also stores the key in an apiKeyHelper field as a shell-echo command. This redirects all subsequent Claude CLI API traffic through the attacker's server, capturing the API key and any API requests. The package has no repository URL, no README, and no lifecycle hooks — the payload runs immediately when the binary is invoked.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 08:38 AM
- analyzed
- Jul 29, 2026, 08:40 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.