⛔ Malware Advisory Detected 2026-09-04 · 10:10 UTC
Confirmed malicious. codelake independently detected this at 2026-09-04 · 10:10 UTC — codelake first-catch — prime-coding-agent was not catalogued in OSV or GHSA at report time. codelake independently identified it and mapped it to the imjustbetterxd AI-CLI Relay Campaign (CLR-2026-3048), which shares one actor and a small set of Replit/Vercel relay backends.. Not yet in any public advisory database at detection time — codelake is the source of record. Static code + dataflow review of the published npm tarballs; no execution, no live callback.
Advisory · CLR-2026-3052

prime-coding-agent — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend

The npm package prime-coding-agent (publisher imjustbetterxd) poses as the “Prime CLI” agentic coding assistant but routes the developer's authenticated AI traffic — API key, prompts and code — to an attacker-controlled backend (apex-api-ten.vercel.app). Part of the AI-CLI Relay Campaign.

CriticalConfirmed maliciousPart of a campaignCredential / data relaycodelake first-catch
What it is & how it works

prime-coding-agent is published to npm by imjustbetterxd and presents as the “Prime CLI” agentic coding assistant. It is one of five packages in the AI-CLI Relay Campaign.

How the relay works. On use, the CLI reads the developer's LLM / provider API key — from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY, provider config) and its own settings — and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's Authorization: Bearer <apiKey> together with the chat prompt and code context, so whoever operates the backend receives the API key and everything the developer sends to their “AI”.

Default backend: apex-api-ten.vercel.app. Unlike the others it is a pure-JS proxy (dist/index.js): it reads provider API keys (e.g. process.env.EXA_API_KEY, NVIDIA_API_KEY, configured provider keys), sets Authorization: Bearer ${apiKey}, and forwards /v1/chat requests to apex-api-ten.vercel.app — matching the actor's GitHub apex-dev / API-server repos.

Unlike the Replit-based siblings in this campaign, prime-coding-agent is a straight JS proxy and does not disable TLS verification — the exfiltration is the mis-routing of the authenticated request itself.

Affected versions

Only one version is published (3.10.6, 2026-03-24) and it is malicious — the entire package is affected.

Timeline
2026-03 – 2026-05
Published
prime-coding-agent published to npm by imjustbetterxd as part of the cluster.
2026-09-04
codelake first-catch
codelake confirms the relay dataflow and maps the package to the campaign (not previously in OSV/GHSA).
Indicators of compromise
🌐Relay backend: apex-api-ten.vercel.app
🧬Pure-JS proxy in dist/index.js: reads EXA_API_KEY/NVIDIA_API_KEY/provider keys, sets Authorization: Bearer, forwards /v1/chat
📤Exfiltrated: LLM/provider API key (Authorization: Bearer), chat prompts and code context sent to the CLI
👤npm publisher imjustbetterxd; GitHub payload host github.com/Marcus-Mok-GH
🔗Campaign: CLR-2026-3048 — AI-CLI Relay Campaign (5 packages, one actor, shared backends)
Remediation
#ActionPriority
1 Uninstall prime-coding-agent; use the legitimate upstream tool instead. Immediate
2 Treat every LLM/provider API key used with it as compromised — rotate it (and revoke any that were set in the environment while it ran). Immediate
3 Hunt egress for apex-api-ten.vercel.app and downloads from github.com/Marcus-Mok-GH. High

Part of the AI-CLI Relay Campaign (CLR-2026-3048). Verified by static code + dataflow review of the published npm tarballs; no execution.