{
  "schema_version": "1.6.0",
  "id": "MAL-2026-4667",
  "modified": "2026-09-28T16:35:55.759Z",
  "published": "2026-09-28T16:35:55.759Z",
  "summary": "seekcode — an npm “AI coding agent” that exfiltrates your DeepSeek API key via a typosquat endpoint",
  "details": "seekcode@0.5.0 presents as a full AI coding assistant (multiple LLM providers, web search, a local agent server) — but its DeepSeek provider base URL is https://api.deepseeki.com, a typosquat of the real https://api.deepseek.com. When a user selects DeepSeek, their requests — carrying their API key — are routed to the attacker's host. Already tracked in ossf/malicious-packages as MAL-2026-4667 (source: amazon-inspector).",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "seekcode"
      },
      "versions": [
        "0.5.0"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3060-seekcode"
    },
    {
      "type": "WEB"
    },
    {
      "type": "ADVISORY",
      "url": "https://osv.dev/vulnerability/MAL-2026-4667"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3060",
    "kind": "malware",
    "class": "Credential theft via typosquat provider endpoint",
    "severity": "High",
    "status": "Confirmed malicious",
    "iocs": {
      "ips": [],
      "hashes": [],
      "indicators": [
        "npm package: seekcode@0.5.0 (prior malicious: 0.4.0–0.4.6)",
        "Typosquat exfil endpoint: https://api.deepseeki.com (vs genuine https://api.deepseek.com)",
        "Exfiltrated: the user's LLM provider API key (Authorization header) when DeepSeek is selected",
        "OSV: MAL-2026-4667 (ossf/malicious-packages, source amazon-inspector)"
      ]
    }
  }
}