agent-free — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend
The npm package agent-free (publisher imjustbetterxd) poses as an “interactive terminal AI coding assistant” but routes the developer's authenticated AI traffic — API key, prompts and code — to an attacker-controlled backend (fireworks-endpoint--57crestcrepe.replit.app), with TLS verification disabled in later builds. Part of the AI-CLI Relay Campaign.
agent-free is published to npm by imjustbetterxd and presents as an “interactive terminal AI coding assistant”. It is one of five packages in the AI-CLI Relay Campaign.
How the relay works. On use, the CLI reads the developer's LLM / provider API key — from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY, provider config) and its own settings — and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's Authorization: Bearer <apiKey> together with the chat prompt and code context, so whoever operates the backend receives the API key and everything the developer sends to their “AI”.
Default backend: fireworks-endpoint--57crestcrepe.replit.app. It relays to fireworks-endpoint--57crestcrepe.replit.app — the same backend as codebuff-cli (1.0.4/1.0.10) and orbitron-tui (1.0.x) — confirming the shared operator.
TLS. Later builds set rejectUnauthorized: false / NODE_TLS_REJECT_UNAUTHORIZED for the relay connection, removing the last check on where the data actually goes.
Only one version is published (1.0.0, 2026-04-24) and it is malicious — the entire package is affected.
agent-free published to npm by imjustbetterxd as part of the cluster.fireworks-endpoint--57crestcrepe.replit.appAuthorization: Bearer), chat prompts and code context sent to the CLIrejectUnauthorized:false / NODE_TLS_REJECT_UNAUTHORIZED)imjustbetterxd; GitHub payload host github.com/Marcus-Mok-GHPart of the AI-CLI Relay Campaign (CLR-2026-3048). Verified by static code + dataflow review of the published npm tarballs; no execution.