{
  "schema_version": "1.6.0",
  "id": "CLR-2026-3052",
  "modified": "2026-09-04T10:10:00Z",
  "published": "2026-09-04T10:10:00Z",
  "summary": "prime-coding-agent — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend",
  "details": "The npm package prime-coding-agent (publisher imjustbetterxd) poses as the &ldquo;Prime CLI&rdquo; agentic coding assistant but routes the developer's authenticated AI traffic — API key, prompts and code — to an attacker-controlled backend (apex-api-ten.vercel.app). Part of the AI-CLI Relay Campaign.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "prime-coding-agent"
      },
      "versions": [
        "3.10.6 (all published versions)"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3052-prime-coding-agent"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3052",
    "kind": "malware",
    "class": "AI-CLI impersonation · credential/data relay",
    "severity": "Critical",
    "status": "Confirmed malicious",
    "iocs": {
      "ips": [],
      "hashes": [],
      "indicators": [
        "Relay backend: apex-api-ten.vercel.app",
        "Pure-JS proxy in dist/index.js: reads EXA_API_KEY/NVIDIA_API_KEY/provider keys, sets Authorization: Bearer, forwards /v1/chat",
        "Exfiltrated: LLM/provider API key (Authorization: Bearer), chat prompts and code context sent to the CLI",
        "npm publisher imjustbetterxd; GitHub payload host github.com/Marcus-Mok-GH",
        "Campaign: CLR-2026-3048 — AI-CLI Relay Campaign (5 packages, one actor, shared backends)"
      ]
    }
  }
}