seekcode — an npm “AI coding agent” that exfiltrates your DeepSeek API key via a typosquat endpoint
[email protected] presents as a full AI coding assistant (multiple LLM providers, web search, a local agent server) — but its DeepSeek provider base URL is https://api.deepseeki.com, a typosquat of the real https://api.deepseek.com. When a user selects DeepSeek, their requests — carrying their API key — are routed to the attacker's host. Already tracked in ossf/malicious-packages as MAL-2026-4667 (source: amazon-inspector).
seekcode ships as an npm package that looks like a legitimate open-source AI coding agent — it wires up real LLM providers (OpenRouter, NVIDIA, Fireworks, Novita, DeepSeek…), web-search APIs, a local /v1/* agent server, and reads project instruction files (AGENTS.md/CLAUDE.md). That legitimate-looking surface is the cover.
Credential theft via typosquat. Its DeepSeek provider base URL resolves to https://api.deepseeki.com — an extra “i”, a typosquat of the genuine https://api.deepseek.com. When the user selects the advertised DeepSeek provider, their chat/completion requests — including the API key sent in the Authorization header — go to the attacker-controlled host instead of DeepSeek.
[email protected] surfaced in codelake's npm scan feed with pkgbehavior agent-surface signals (agent-config-tamper, child-spawn-dynamic). Because those signals also fire on legitimate AI-agent tooling, we did NOT stop there: on flag-safe static review of the published tarball we compared every provider base URL against its real vendor and found the DeepSeek endpoint pointing at the typosquat api.deepseeki.com.
This is corroborated by ossf/malicious-packages record MAL-2026-4667 (source: amazon-inspector), and by our own prior confirmation of versions 0.4.0–0.4.6.
Analysed: 0.5.0; prior 0.4.0–0.4.6 previously confirmed malicious. The OSV malicious-packages record covers the package as malicious.
[email protected] (prior malicious: 0.4.0–0.4.6)https://api.deepseeki.com (vs genuine https://api.deepseek.com)MAL-2026-4667 (ossf/malicious-packages, source amazon-inspector)Verified by static code review of the published npm tarball; no execution, no live callback.
The malicious behaviour is a single typosquat provider URL hidden inside an otherwise plausible AI-agent codebase.
Corroborated by ossf/malicious-packages MAL-2026-4667 (amazon-inspector) and our prior confirmation of 0.4.0–0.4.6.