Advisory index · 78 entries

Security advisories

Verified supply-chain findings — every case is disclosed to the maintainer or vendor first. Malware and vulnerability findings are named on publication; credential-leak identities are revealed only after a coordinated-disclosure deadline. Credential values are always redacted.

⌕
Ecosystem▾
src
78 of 78 entries
◆codelake CLR-2026-3066 2026-10-02
akiflow-toolkit 1.7.0

akiflow-toolkit — scrapes your Akiflow session out of Chrome's credential store

Risky tool Medium
◆codelake CLR-2026-3065 2026-10-02
@agentgates/cli 0.74.0

@agentgates/cli — autonomous crypto/password agent that injects itself into your agent config

Risky tool Medium
◆codelake CLR-2026-3064 2026-10-02
mecord-connect 2.0.2

mecord-connect — remote-operator credential access behind a "ChatGPT automation" cover

Malware High
◆codelake CLR-2026-3063 2026-10-01
loka-ai-router 0.0.0-beta.20260926.fd08b17

loka-ai-router — install-time binary downloads and shell installers

Risky tool Medium
◆codelake CLR-2026-3062 2026-10-01
@onescience/onecode 1.14.50-202609231732

@onescience/onecode — install-time dropper

Malware Critical
◆codelake CLR-2026-3061 2026-09-29
aicall-cli-x 0.0.21

A commercial AI sales-call CLI that sends its users' login credentials in plaintext HTTP to a hardcoded IP

Risky tool High
◆codelake CLR-2026-3060 2026-09-28
seekcode 0.5.0

seekcode — an npm “AI coding agent” that exfiltrates your DeepSeek API key via a typosquat endpoint

Malware High
◆codelake CLR-2026-3059 2026-09-28
squeez 1.48.4

squeez — an npm package whose postinstall curl|sh-drops a remote script and native binary, then rewrites Claude Code hooks

Malware Critical
◆codelake CLR-2026-3058 2026-09-26
alihelp.xyz hijack campaign 4 add-ons

alihelp.xyz / Shadow Code — a Firefox affiliate-commission-hijacking campaign across four AliExpress add-ons

Malware Medium
◆codelake CLR-2026-3057 2026-09-26
AliExpress Rating Checker 1.4.6

AliExpress Rating & Fake Review Checker — a Firefox add-on that hijacks AliExpress affiliate commissions and reports your product clicks to alihelp.xyz, while declaring it collects no data

Malware Medium
◆codelake CLR-2026-3056 2026-09-26
AliExpress Image/Video Downloader 2.3.4

AliExpress Image and Video Downloader — a Firefox add-on that hijacks AliExpress affiliate commissions and reports your product clicks to alihelp.xyz, while declaring it collects no data

Malware Medium
◆codelake CLR-2026-3055 2026-09-26
Search by Image (AliExpress) 2.2.1

Search by Image: AliExpress & Alibaba — a Firefox add-on that silently hijacks AliExpress affiliate commissions with no consent, and requests access to every site you visit

Malware Medium
◆codelake CLR-2026-3054 2026-09-26
AliHelp 2.0.5

AliHelp — a Firefox “AliExpress shopping assistant” that hijacks affiliate commissions and tracks your shopping

Malware Medium
◆codelake CLR-2026-3053 2026-09-07
tsshare 1.0.5 – 1.0.19 (all published)

tsshare — a Tushare-impersonating PyPI client that hides its endpoint in base64 and exfiltrates your API token and a hardware fingerprint

Malware High
◆codelake CLR-2026-3049 2026-09-04
orbitron-tui all 84 versions (0.1.2–1.0.29)

orbitron-tui — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend

Part of a campaign Critical
◆codelake CLR-2026-3050 2026-09-04
orbitron-cli 1.0.1 (all published versions)

orbitron-cli — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend

Part of a campaign Critical
◆codelake CLR-2026-3051 2026-09-04
agent-free 1.0.0 (all published versions)

agent-free — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend

Part of a campaign Critical
◆codelake CLR-2026-3052 2026-09-04
prime-coding-agent 3.10.6 (all published versions)

prime-coding-agent — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend

Part of a campaign Critical
◆codelake CLR-2026-3048 2026-09-04
AI-CLI Relay Campaign 5 packages

A cluster of AI-coding-CLI impersonations (npm) that relay your API key, code and prompts to attacker backends

Campaign · 5 packages Critical
◆codelake CLR-2026-3046 2026-09-03
codebuff-cli 1.0.4–1.1.12

codebuff-cli — a codebuff impersonation that relays your API key, code and prompts to an attacker backend

Impersonation Critical
◆codelake CLR-2026-3047 2026-09-03
@yancyyu/agentcli 1.9.9–1.10.0

@yancyyu/agentcli — a Feishu/Lark credential stealer with a keychain-decrypting telemetry worker

Lark credential theft Critical
◆codelake CLR-2026-3045 2026-09-03
AzureCdnInfo.edrtester 1.0.4

AzureCdnInfo.edrtester — a VS Code extension that beacons out with host recon behind HTTP Host-header domain fronting

Domain fronting Critical
◆codelake CLR-2026-3044 2026-08-12
cc-skills-helper 1.0.6 (all 7 releases affected)

Password-protected remote-fetch-and-execute dropper in the npm package cc-skills-helper (all 7 releases)

Remote fetch-and-execute dropper Critical
◆codelake CLR-2026-3043 2026-08-11
advanced-responsive-video-embedder 10.8.7

Supply-chain backdoor in the WordPress plugin Advanced Responsive Video Embedder (10.8.7)

Supply-chain backdoor Critical
◆codelake CLR-2026-3042 2026-08-05
Shai-Hulud / ChainDrop npm worm multiple (see IOC list)

Shai-Hulud / ChainDrop — self-propagating npm worm across 665 package versions

npm worm Critical
◆codelake CLR-2026-3041 2026-07-29
@types-beta/sdk 0.1.3

@types-beta/sdk — an import-time Windows RAT hiding behind the @types namespace

Native-binary dropper (RAT) Critical
◆codelake CLR-2026-3039 2026-07-21
date-format-utils-xz 1.0.0 – 1.0.4 (all versions)

date-format-utils-xz — a metadata harvester that escalated to a reverse shell

Reverse shell (RCE) in 1.0.4 Critical
◆codelake CLR-2026-3040 2026-07-21
faust-cont 1.0.0

faust-cont — an install-hook dropper that runs remote code via Deno

Malware Critical
◆codelake CLR-2026-3038 2026-07-20
supplyhub 1.0.2

supplyhub — a postinstall SSH-key & credential stealer

SSH & env stealer Critical
◆codelake CLR-2026-3037 2026-07-17
tailwind-gutenberg-block-zero 1.0.0

tailwind-gutenberg-block-zero — an install-time Windows dropper posing as a Tailwind Gutenberg block

Install-hook dropper Critical
◆codelake CLR-2026-3036 2026-07-16
@across-toolkit/typescript-config 99.0.0

Dependency-confusion package that steals AWS, SSH and npm credentials from Across Protocol developers

Dependency confusion Critical
◆codelake CLR-2026-3035 2026-07-15
none123s 1.1.7

npm package that steals your SSH keys, AWS creds and npm token on npm install

Credential stealer Critical
◆codelake CLR-2026-3034 2026-07-15
node-procmetrics 1.0.3

Fake “system metrics” npm package that opens a remote-command backdoor on npm install

C2 RAT Critical
◆codelake CLR-2026-3033 2026-07-12
polymarket-mcp-v2 2.1.6

Fake Polymarket MCP server that installs an SSH backdoor on npm install

SSH backdoor Critical
◆codelake CLR-2026-3032 2026-07-11
Admin Note 1.1

Unauthenticated SQL Injection in the WordPress plugin Admin Note (1.1)

SQL Injection Critical
◆codelake CLR-2026-3031 2026-07-11
Auto Listings 2.7.3

Unauthenticated SQL Injection in the WordPress plugin Auto Listings (2.7.3)

SQL Injection Critical
◆codelake CLR-2026-3030 2026-07-11
WP Page Extension 1.1

SQL Injection in the WordPress plugin WP Page Extension (1.1)

SQL Injection High
◆codelake CLR-2026-3029 2026-07-11
Voting for a photo 1.2

Unauthenticated SQL Injection in the WordPress plugin Voting for a photo (1.2)

SQL Injection Critical
◆codelake CLR-2026-3028 2026-07-10
Aeroscroll Gallery 1.0.13

Unauthenticated SQL Injection in the WordPress plugin Aeroscroll Gallery (1.0.13)

SQL Injection Critical
◆codelake CLR-2026-3027 2026-07-10
asAffili 1.1.1

Unauthenticated SQL Injection in the WordPress plugin asAffili (1.1.1)

SQL Injection Critical
◆codelake CLR-2026-3026 2026-07-10
polipoli-pak 1.0.2

Fake React UI helper that steals your whole environment on install

Environment stealer Critical
◆codelake CLR-2026-3000 2026-07-09
@wagni_bot/metemask-sdk 1.2.0

Fake MetaMask (misspelled "metemask") SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3001 2026-07-09
@wagni_bot/metamask 1.0.0

Fake MetaMask SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3002 2026-07-09
@wagni_bot/binance-sdk 1.2.0

Fake Binance SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3003 2026-07-09
@wagni_bot/solana-sdk 1.2.0

Fake Solana SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3004 2026-07-09
@wagni_bot/jupiter-sdk 1.2.0

Fake Jupiter (Solana DEX aggregator) SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3005 2026-07-09
@wagni_bot/orca-sdk 1.2.0

Fake Orca (Solana DEX) SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3006 2026-07-09
@wagni_bot/meteora-sdk 1.2.0

Fake Meteora (Solana DEX) SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3007 2026-07-09
@wagni_bot/pumpfun-sdk 1.2.0

Fake Pump.fun SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3008 2026-07-09
@wagni_bot/opensea 1.0.0

Fake OpenSea SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3009 2026-07-09
@wagni_bot/opensea-sdk 1.2.0

Fake OpenSea SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3010 2026-07-09
@wagni_bot/polymarket 1.0.0

Fake Polymarket SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3011 2026-07-09
@wagni_bot/polymarket-sdk 1.2.0

Fake Polymarket SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3012 2026-07-09
@wagni_bot/hyperliquid 1.0.0

Fake Hyperliquid SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3013 2026-07-09
@wagni_bot/hyperliquid-sdk 1.2.0

Fake Hyperliquid SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3014 2026-07-09
@wagni_bot/polygon 1.0.0

Fake Polygon SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3015 2026-07-09
@wagni_bot/polygon-sdk 1.2.0

Fake Polygon SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3016 2026-07-09
@wagni_bot/bsc 1.0.0

Fake BNB Smart Chain (BSC) SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3017 2026-07-09
@wagni_bot/bsc-sdk 1.2.0

Fake BNB Smart Chain (BSC) SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3018 2026-07-09
@wagni_bot/eth 1.0.0

Fake Ethereum SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3019 2026-07-09
@wagni_bot/eth-agent 1.2.0

Fake Ethereum SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3020 2026-07-09
@wagni_bot/ethereum-wallet 1.2.0

Fake an Ethereum wallet library SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3021 2026-07-09
@wagni_bot/web3 1.0.0

Fake web3.js SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3022 2026-07-09
@wagni_bot/web3-agent 1.2.0

Fake web3.js SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3023 2026-07-09
@wagni_bot/web3-toolkit 1.2.0

Fake web3.js SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-3024 2026-07-09
@wagni_bot/wagni 1.0.0

Fake the campaign's own namesake handle SDK that steals your SSH keys and crypto wallets on install

SSH-key + wallet stealer Critical
◆codelake CLR-2026-2999 2026-07-09
antsrcsrctest 1.0.0

Dependency-confusion probe that steals cloud credentials + your whole environment on install

Dependency confusion Critical
◆codelake CLR-2026-2998 2026-07-08
88狗 1.0.1.0

A Steam “accelerator” extension that reads your Steam session and proxies your Steam traffic

Risky tool High
◆codelake CLR-2026-2997 2026-07-08
AutoKling 1.0.6.0

A Chrome extension that strips Kling’s security headers to farm the AI service

Risky tool High
◆codelake CLR-2026-2996 2026-07-07
AutoHailuo 0.0.12.0

A Chrome extension that strips a site’s security headers to farm an AI service

Risky tool High
◆codelake CLR-2026-2995 2026-07-06
monotenant 1.0.53

A bulk-mail & credential-cracking toolkit shipped as an npm package

Abuse tooling High
◆codelake CLR-2026-2994 2026-07-05
logger-daemon-regex 1.0.124

A crypto-wallet & secret stealer disguised as an Autodesk Forge integration

Wallet / secret stealer Critical
◆codelake CLR-2026-0849 2026-07-02
LeetMentor 1.1

Three live AI-provider keys shipped as an “inbuilt” free tier in LeetMentor

Credential Exposure High
◆codelake CLR-2026-2990 2026-07-02
datefmt-helper 1.0.0

A download-and-execute dropper disguised as a date-formatting utility

Install-hook dropper Critical
◆codelake CLR-2026-2991 2026-07-01
fmt-date-lite 1.0.0

A date-utility dropper — and the campaign it belongs to

Install-hook dropper Critical
◆codelake CLR-2026-2989 2026-06-30
coral-wraith 1.0.8

Anatomy of an npm registry-hijack: /etc/hosts redirection and publish-token theft

Technique dissection Critical
◆codelake CLR-2026-2993 2026-06-25
colorpicker-ui 1.2.5

Cloud-credential theft disguised as a React colour picker

Cloud-metadata SSRF Critical
◆codelake CLR-2026-2988 2026-06-24
zod-pino 1.0.127

A multi-stage credential stealer hiding inside a fake “zod-pino” utility

Stealer / RAT Critical