⛔ Malware Advisory Detected 2026-09-28
Confirmed malicious. codelake independently detected this at 2026-09-28 — Independently detected in codelake's npm scan feed and confirmed on flag-safe static review (found the api.deepseeki.com typosquat by comparing each provider base URL to its real vendor). Already published in ossf/malicious-packages as MAL-2026-4667 (amazon-inspector) — this advisory corroborates and links that record; not a codelake first-catch.. Also documented publicly: MAL-2026-4667 (OSV / ossf-malicious-packages (amazon-inspector)). Static code review of the published npm tarball; no execution.
Advisory · CLR-2026-3060

seekcode — an npm “AI coding agent” that exfiltrates your DeepSeek API key via a typosquat endpoint

[email protected] presents as a full AI coding assistant (multiple LLM providers, web search, a local agent server) — but its DeepSeek provider base URL is https://api.deepseeki.com, a typosquat of the real https://api.deepseek.com. When a user selects DeepSeek, their requests — carrying their API key — are routed to the attacker's host. Already tracked in ossf/malicious-packages as MAL-2026-4667 (source: amazon-inspector).

HighConfirmed maliciousOSV MAL-2026-4667
What it is & how it works

seekcode ships as an npm package that looks like a legitimate open-source AI coding agent — it wires up real LLM providers (OpenRouter, NVIDIA, Fireworks, Novita, DeepSeek…), web-search APIs, a local /v1/* agent server, and reads project instruction files (AGENTS.md/CLAUDE.md). That legitimate-looking surface is the cover.

Credential theft via typosquat. Its DeepSeek provider base URL resolves to https://api.deepseeki.com — an extra “i”, a typosquat of the genuine https://api.deepseek.com. When the user selects the advertised DeepSeek provider, their chat/completion requests — including the API key sent in the Authorization header — go to the attacker-controlled host instead of DeepSeek.

How we found it

[email protected] surfaced in codelake's npm scan feed with pkgbehavior agent-surface signals (agent-config-tamper, child-spawn-dynamic). Because those signals also fire on legitimate AI-agent tooling, we did NOT stop there: on flag-safe static review of the published tarball we compared every provider base URL against its real vendor and found the DeepSeek endpoint pointing at the typosquat api.deepseeki.com.

This is corroborated by ossf/malicious-packages record MAL-2026-4667 (source: amazon-inspector), and by our own prior confirmation of versions 0.4.0–0.4.6.

Affected versions

Analysed: 0.5.0; prior 0.4.0–0.4.6 previously confirmed malicious. The OSV malicious-packages record covers the package as malicious.

Timeline
2026-09-28
codelake detection (0.5.0)
Flagged in the npm scan feed; the DeepSeek typosquat endpoint confirmed on flag-safe static review; corroborated against OSV MAL-2026-4667 and our prior 0.4.x confirmation.
Indicators of compromise
📦npm package: [email protected] (prior malicious: 0.4.0–0.4.6)
🌐Typosquat exfil endpoint: https://api.deepseeki.com (vs genuine https://api.deepseek.com)
🔑Exfiltrated: the user's LLM provider API key (Authorization header) when DeepSeek is selected
🔖OSV: MAL-2026-4667 (ossf/malicious-packages, source amazon-inspector)
Remediation
#ActionPriority
1 Uninstall seekcode. Immediate
2 Rotate any LLM/API keys configured in seekcode — especially DeepSeek keys, which may have been sent to api.deepseeki.com. Immediate
3 Review outbound traffic/DNS logs for api.deepseeki.com. Advised

Verified by static code review of the published npm tarball; no execution, no live callback.

The malicious behaviour is a single typosquat provider URL hidden inside an otherwise plausible AI-agent codebase.

Corroborated by ossf/malicious-packages MAL-2026-4667 (amazon-inspector) and our prior confirmation of 0.4.0–0.4.6.