{
  "schema_version": "1.6.0",
  "id": "CLR-2026-3046",
  "modified": "2026-09-03T11:30:00Z",
  "published": "2026-09-03T11:30:00Z",
  "summary": "codebuff-cli — a codebuff impersonation that relays your API key, code and prompts to an attacker backend",
  "details": "An npm package that impersonates the official codebuff (README copied verbatim). Its bundled binary defaults the backend to attacker-controlled endpoints, silently relaying authenticated requests — API key, code, context and messages. Later versions pull a mutable payload from a foreign GitHub repo and even disable TLS certificate verification for it.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "codebuff-cli"
      },
      "versions": [
        "1.0.4–1.1.12"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3046-codebuff-cli"
    },
    {
      "type": "WEB",
      "url": "https://osv.dev/vulnerability/MAL-2026-4533"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3046",
    "kind": "malware",
    "class": "Impersonation · credential/data relay",
    "severity": "Critical",
    "status": "Confirmed malicious",
    "iocs": {
      "ips": [],
      "hashes": [
        "sha256:970fbb955507af8f178a7ddb47d62662ce6f5a58c92773a080a3753685552211",
        "sha256:8f15aeaebbb2857afce7a2117c0d55a8184f9f35500b89c9c4f564556ee33530",
        "sha256:d50cb1099a1b894be2f2055ff9cccca773e7c0e7397bf4a940f287d9603f4e0c"
      ],
      "indicators": [
        "Relay backend (1.0.4 / 1.0.10): fireworks-endpoint--57crestcrepe.replit.app",
        "Relay backend (1.1.3): fireworks-api-backend.vercel.app",
        "Foreign payload repo (1.0.25): github.com/Marcus-Mok-GH/codebuff-cli (mutable latest)",
        "1.1.3 disables TLS certificate verification for the launched payload",
        "tarball sha256 1.0.4 970fbb955507af8f178a7ddb47d62662ce6f5a58c92773a080a3753685552211",
        "tarball sha256 1.0.10 8f15aeaebbb2857afce7a2117c0d55a8184f9f35500b89c9c4f564556ee33530",
        "tarball sha256 1.1.3 d50cb1099a1b894be2f2055ff9cccca773e7c0e7397bf4a940f287d9603f4e0c",
        "Malicious versions (29): 1.0.4, 1.0.10, 1.0.11, 1.0.12, 1.0.14, 1.0.15, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.24, 1.0.26, 1.0.27, 1.0.28, 1.1.0, 1.1.1, 1.1.2, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.10, 1.1.11, 1.1.12, 1.1.3. Suspicious: 1.0.16, 1.0.25."
      ]
    }
  }
}